Tag

#D-Link

newsCRITICAL 9.8

Critical Command Injection Vulnerability in D-Link DWR-M961 Devices (CVE-2026-71945)

A critical command injection vulnerability (CVE-2026-71945) has been discovered in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. This vulnerability allows a remote attacker to inject arbitrary malicious commands, resulting in command execution with root privileges. Affected organizations should update their firmware to version 1.1.5_C1_202607071108 or later.

1 source
articleCRITICAL 9.8

Critical Command Injection Vulnerability in D-Link DWR-M961 Devices

A critical command injection vulnerability (CVE-2026-71944) has been discovered in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. This vulnerability allows a remote attacker to inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. The vulnerability has a CVSS score of 9.8 and is considered critical. Immediate patching is recommended to prevent potential exploitation.

1 source
articleCRITICAL 9.8

Critical Buffer Overflow Vulnerability in D-Link DWR-M961 Devices

A critical buffer overflow vulnerability (CVE-2026-71957) has been discovered in D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044. This vulnerability allows a remote attacker to execute arbitrary commands or cause the device to crash by crafting a specific payload. The vulnerability has a CVSS score of 9.8 and is considered critical. Organizations using affected devices should apply patches or mitigations immediately.

1 source