What is CVE-2026-71944?
This CVE describes a command injection vulnerability in the '/boafrm/formLtefotaUpgradeQuectel' interface of D-Link DWR-M961 devices (hardware version C1, firmware before 1.1.5_C1_202607071108). A remote attacker can inject arbitrary commands via the 'fota_url' field, leading to command execution. It is recommended to update the firmware of affected devices to the latest version.
Azərbaycanca: Bu CVE, D-Link DWR-M961 cihazlarının (hardware versiyası C1, 1.1.5_C1_202607071108-dən əvvəlki firmware) 'formLtefotaUpgradeQuectel' interfeysindəki əmr inyeksiyası zəifliyini təsvir edir. Uzaqdan hücumçu 'fota_url' sahəsinə zərərli əmrlər daxil edərək cihazda ixtiyari əmrlər icra edə bilər. Təsirlənmiş cihazların firmware-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which D-Link device is affected by CVE-2026-71944?
This vulnerability affects D-Link DWR-M961 devices with hardware version C1.
What is the recommended mitigation for CVE-2026-71944?
It is recommended to update the firmware of affected devices to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.