Critical Command Injection Vulnerability in D-Link DWR-M961 Devices
A critical command injection vulnerability (CVE-2026-71944) has been discovered in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. This vulnerability allows a remote attacker to inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. The vulnerability has a CVSS score of 9.8 and is considered critical. Immediate patching is recommended to prevent potential exploitation.