Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-71957: D-Link DWR-M961: Uncontrolled Data Writes Cause Crash or Command Execution
CVE-2026-71957 · published 27 days ago
Summary
D-Link DWR-M961 devices with specific hardware and software versions are at risk of a buffer overflow vulnerability. This could allow an attacker to crash the device or execute unauthorized commands. Update the device to the latest version to mitigate this risk.
What to do
- Update d-link corporation dwr-m961 to version 1.1.5_C1_202607071108 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link corporation | dwr-m961 | < 1.1.5_C1_202607071108 |
Original advisory text
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly l...
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
References
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
Timeline
Published8 Aug 2026
Updated3 Sep 2026
First seen8 Aug 2026
Monitor software like this
Free during beta