VYPR
Vypr IntelligenceAI-generatedAug 8, 2026· 15 CVEs

D-Link DWR-M961: 15 Critical Command Injection & Buffer Overflow Flaws Disclosed Together

D-Link DWR-M961 routers are hit with 15 critical command injection and buffer overflow vulnerabilities, all disclosed on August 8, 2026.

Key findings

  • 15 critical vulnerabilities disclosed on August 8, 2026, for D-Link DWR-M961 routers.
  • All vulnerabilities carry a CVSSv3 score of 9.8, indicating critical severity.
  • Flaws include command injection and buffer overflow vulnerabilities across multiple interfaces.
  • Affected devices are DWR-M961 hardware version C1 with specific software/firmware versions.
  • Patched firmware version 1.1.5_C1_202607071108 is available for command injection flaws.

On August 8, 2026, a significant batch of 15 critical vulnerabilities was disclosed for D-Link's DWR-M961 router, all sharing the same CVSSv3 score of 9.8. These vulnerabilities, affecting hardware version C1 and specific software/firmware versions, primarily revolve around command injection and buffer overflow flaws, potentially allowing remote attackers to execute arbitrary code with root privileges.

The disclosed vulnerabilities can be broadly categorized into command injection and buffer overflow types.

Command Injection Vulnerabilities: Several CVEs detail command injection flaws within various CGI interfaces and configuration pages. For instance, CVE-2026-71956 in app.cgi allows injection into the netDig.ping.dst field, CVE-2026-71955 in /boafrm/formWsc targets fields like localPin and targetAPSsid, and CVE-2026-71954 in /boafrm/formL2tpv3ConfigSetup affects tunnelid and sessionid. Other command injection vulnerabilities were found in interfaces such as /boafrm/formNtp (CVE-2026-71953), /boafrm/formIMEISetup (CVE-2026-71951), /boafrm/formSmsManage (CVE-2026-71950), /boafrm/formUSSDSetup (CVE-2026-71949), /boafrm/formDebugDiagnosticRun (CVE-2026-71948), /boafrm/formTracerouteDiagnosticRun (CVE-2026-71947), /boafrm/formPingDiagnosticRun (CVE-2026-71946), /boafrm/formLtefotaUpgradeFibocom (CVE-2026-71945), and /boafrm/formLtefotaUpgradeQuectel (CVE-2026-71944). These vulnerabilities enable attackers to inject malicious commands through various input fields, leading to command execution.

Buffer Overflow Vulnerabilities: CVE-2026-71958, found in the quicksetup.cgi interface, and CVE-2026-71957, located in the app.cgi interface, are critical buffer overflow vulnerabilities. Attackers can exploit these by sending overly long strings to specific fields, such as test4, ssid2, and username in CVE-2026-71958, or netAcc.addlist[].name in CVE-2026-71957. Successful exploitation can lead to arbitrary command execution or device instability.

Affected Versions and Patching: The vulnerabilities impact D-Link DWR-M961 devices with hardware version C1. Specifically, CVE-2026-71958 and CVE-2026-71957 affect software version 1.1.2_C1_202602110044. The command injection vulnerabilities, including CVE-2026-71954 through CVE-2026-71944, affect firmware versions prior to 1.1.5_C1_202607071108. D-Link has released firmware version 1.1.5_C1_202607071108 to address these command injection flaws. Users are strongly advised to update their devices to the patched firmware to mitigate these critical risks.

The simultaneous disclosure of 15 critical vulnerabilities highlights a significant security concern for D-Link DWR-M961 users. The concentration of command injection and buffer overflow flaws, all rated critical, underscores the importance of timely patching and security updates for network edge devices. Users should verify their device's hardware and firmware versions and apply the available updates immediately to prevent potential exploitation.

AI-written article. Grounded in 15 CVE records listed below.