Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-71954: D-Link DWR-M961 Firmware Command Injection Risk
CVE-2026-71954 · published 27 days ago
Summary
D-Link DWR-M961 devices with older firmware are at risk of being controlled by a hacker. If exploited, this vulnerability could allow an attacker to access and manipulate the device's settings and data. D-Link recommends updating the firmware to version 1.1.5_C1_202607071108 or later to fix this issue.
What to do
- Update d-link corporation dwr-m961 to version 1.1.5_C1_202607071108 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link corporation | dwr-m961 | < 1.1.5_C1_202607071108 |
Original advisory text
D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
References
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published8 Aug 2026
Updated30 Aug 2026
First seen8 Aug 2026
Monitor software like this
Free during beta