What is CVE-2026-71945?
This CVE describes a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface of D-Link DWR-M961 devices (hardware version C1, firmware before 1.1.5_C1). A remote attacker can inject malicious commands via the fota_url field to execute arbitrary code. Affected users should immediately update to the latest firmware.
Azərbaycanca: Bu CVE D-Link DWR-M961 cihazlarında (hardware versiya C1, firmware 1.1.5_C1-dən əvvəl) /boafrm/formLtefotaUpgradeFibocom interfeysindəki command injection zəifliyidir. Remote attacker fota_url sahəsinə sızaraq ixtiyari əmrlər icra edə bilir. Təsirlənən istifadəçilər dərhal firmware-i son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which component is affected by CVE-2026-71945 in the D-Link DWR-M961 device?
The vulnerability affects the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can perform a command injection by manipulating the fota_url parameter.
What should users do to protect against CVE-2026-71945?
Users of the D-Link DWR-M961 hardware version C1 should immediately update the firmware to version 1.1.5_C1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.