What is CVE-2026-71949?
A command injection vulnerability exists in the /boafrm/formUSSDSetup interface of D-Link DWR-M961 devices. A remote attacker can inject malicious commands via the ussdValue and selectMenuValue fields to compromise the system. Users should immediately upgrade their firmware to the latest security update.
Azərbaycanca: D-Link DWR-M961 cihazlarında /boafrm/formUSSDSetup interfeysində command injection zəifliyi aşkarlanıb. Uzaqdan hücumçu ussdValue və selectMenuValue sahələrinə zərərli əmrlər əlavə edərək sistemi ələ keçirə bilər. İstifadəçilər dərhal firmware versiyasını ən son təhlükəsizlik yeniləməsi ilə yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
In which interface of the D-Link DWR-M961 was the CVE-2026-71949 vulnerability discovered?
The vulnerability was discovered in the /boafrm/formUSSDSetup interface.
Which fields can an attacker use to compromise the system via the CVE-2026-71949 vulnerability?
An attacker can compromise the system by injecting malicious commands into the ussdValue and selectMenuValue fields.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.