Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-71956: D-Link DWR-M961 devices vulnerable to remote command execution
CVE-2026-71956 · published 27 days ago
Summary
D-Link DWR-M961 devices with specific hardware and software versions are at risk of being controlled remotely by an attacker. This could allow an attacker to access and manipulate the device's settings, potentially disrupting its functionality or using it to launch further attacks. Update to the latest version of the software to mitigate this risk.
What to do
- Update d-link corporation dwr-m961 to version 1.1.5_C1_202607071108 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link corporation | dwr-m961 | < 1.1.5_C1_202607071108 |
Original advisory text
D-Link DWR-M961 Command Injection via app.cgi
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.
References
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published8 Aug 2026
Updated30 Aug 2026
First seen8 Aug 2026
Monitor software like this
Free during beta