What is CVE-2026-71951?
A command injection vulnerability exists in the /boafrm/formIMEISetup interface of D-Link DWR-M961 devices with hardware version C1 and firmware before 1.1.5_C1_2026, allowing remote attackers to execute arbitrary commands via the IMEI_value field. This critical flaw could lead to full device compromise if exploited. Firmware should be updated immediately to mitigate the risk.
Azərbaycanca: D-Link DWR-M961 routerinin C1 hardware versiyası və 1.1.5_C1_2026-dən əvvəlki firmware üçün aşkar edilmiş bu boşluq, "formIMEISetup" interfeysindəki IMEI_value sahəsinə xüsusi hazırlanmış əmrlər daxil etməklə uzaqdan kod icrasına imkan verir. Bu zəiflik uğurla istismar edildikdə, hücumçu cihazda ixtiyari əmrlər icra edə bilər. Təsirə məruz qalan cihazların firmware-ini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Where exactly is the CVE-2026-71951 vulnerability located?
The flaw is located in the IMEI_value field of the /boafrm/formIMEISetup interface on D-Link DWR-M961 routers with hardware version C1 and firmware before 1.1.5_C1_2026.
What is the impact of exploiting this vulnerability?
Successful exploitation allows remote attackers to execute arbitrary commands on the device, potentially leading to full device compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.