What is CVE-2026-71946?
CVE-2026-71946 is a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface of D-Link DWR-M961 devices (hardware version C1, firmware before 1.1.5_C1_2026). A remote attacker can inject malicious commands via the host field to achieve arbitrary command execution. Updating to the latest firmware version is recommended.
Azərbaycanca: CVE-2026-71946 D-Link DWR-M961 cihazlarında (C1 hardware versiyası, 1.1.5_C1_2026-dən əvvəlki firmware) /boafrm/formPingDiagnosticRun interfeysində command injection zəifliyidir. Uzaqdan hücumçu host sahəsinə zərərli əmrlər daxil edərək cihazda ixtiyari əmr icrasına nail ola bilər. Cihazınızı ən son firmware versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which D-Link device is affected by CVE-2026-71946?
D-Link DWR-M961 devices, specifically the C1 hardware version.
What should I do to protect against CVE-2026-71946?
Update your device to the latest firmware version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.