Tag
#D-Link
Critical Command Injection Vulnerability in D-Link DWR-M961 Devices (CVE-2026-71945)
A critical command injection vulnerability (CVE-2026-71945) has been discovered in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. This vulnerability allows a remote attacker to inject arbitrary malicious commands, resulting in command execution with root privileges. Affected organizations should update their firmware to version 1.1.5_C1_202607071108 or later.
Critical Command Injection Vulnerability in D-Link DWR-M961 Devices
A critical command injection vulnerability (CVE-2026-71944) has been discovered in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. This vulnerability allows a remote attacker to inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. The vulnerability has a CVSS score of 9.8 and is considered critical. Immediate patching is recommended to prevent potential exploitation.
Critical Buffer Overflow Vulnerability in D-Link DWR-M961 Devices
A critical buffer overflow vulnerability (CVE-2026-71957) has been discovered in D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044. This vulnerability allows a remote attacker to execute arbitrary commands or cause the device to crash by crafting a specific payload. The vulnerability has a CVSS score of 9.8 and is considered critical. Organizations using affected devices should apply patches or mitigations immediately.