What is CVE-2026-71948?
A command injection vulnerability exists in the /boafrm/formDebugDiagnosticRun interface of D-Link DWR-M961 devices with a specific firmware version. A remote attacker can inject malicious commands into the host field, leading to arbitrary command execution. It is recommended to update the device to the latest firmware version.
Azərbaycanca: D-Link DWR-M961 cihazlarında müəyyən proqram təminatı versiyasında /boafrm/formDebugDiagnosticRun interfeysində command injection zəifliyi aşkarlanıb. Uzaqdan hücum edən şəxs host sahəsinə zərərli əmrlər daxil edərək cihazda ixtiyari kod icrasına səbəb ola bilər. Cihazı ən son proqram təminatına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which interface on my D-Link DWR-M961 device is affected by CVE-2026-71948?
The vulnerability exists in the /boafrm/formDebugDiagnosticRun interface of the device.
What should I do to protect against CVE-2026-71948?
It is recommended to update your device to the latest firmware version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.