VYPR

DWR-M961

by Dlink

CVEs (20)

  • CVE-2026-71958CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary…

  • CVE-2026-71957CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by…

  • CVE-2026-71956CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command…

  • CVE-2026-71955CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and…

  • CVE-2026-71954CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid…

  • CVE-2026-71953CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in…

  • CVE-2026-71952CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in…

  • CVE-2026-71951CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in…

  • CVE-2026-71950CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting…

  • CVE-2026-71949CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue…

  • CVE-2026-71948CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting…

  • CVE-2026-71947CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer…

  • CVE-2026-71946CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting…

  • CVE-2026-71945CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field,…

  • CVE-2026-71944CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field,…

  • CVE-2025-3785HigApr 18, 2025
    risk 0.58cvss 8.8epss 0.11

    A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer…

  • CVE-2025-13304HigNov 17, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The…

  • CVE-2026-1625MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boafrm/formSmsManage of the component SMS Message. Performing a manipulation of the argument action_value results in command injection. The attack may be…

  • CVE-2026-1624MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.03

    A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. The attack can be launched remotely. The…

  • CVE-2026-1596MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit…