Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-71958: D-Link DWR-M961: Uncontrolled Data Execution

CVE-2026-71958 · published 27 days ago
Summary

D-Link DWR-M961 devices with specific hardware and software versions are vulnerable to an attack that can cause the device to crash or allow an attacker to execute unauthorized commands. This vulnerability can be exploited remotely, making it a concern for users who connect their devices to the internet. Users with affected devices should update to a newer version of the software to address this issue.

What to do
  • Update d-link corporation dwr-m961 to version 1.1.5_C1_202607071108 or later.
Affected software
VendorProductAffected versions
d-link corporation dwr-m961 < 1.1.5_C1_202607071108
Original advisory text
D-Link DWR-M961 Buffer Overflow via quicksetup.cgi
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
Timeline
Published8 Aug 2026
Updated3 Sep 2026
First seen8 Aug 2026
Sources
CVE-2026-71958 · MITRE
Monitor software like this
Free during beta