What is CVE-2026-71952?
CVE-2026-71952 is a command injection vulnerability found in D-Link DWR-M961 devices with hardware version C1 running firmware versions prior to 1.1.5_C1_2026. A remote attacker can exploit the /boafrm/formPinManageSetup interface by injecting malicious commands into the oldPIn field, allowing arbitrary command execution on the device. Users should immediately upgrade to the latest firmware version and restrict access to the management interface.
Azərbaycanca: CVE-2026-71952, D-Link DWR-M961 cihazlarının C1 hardware versiyasında 1.1.5_C1_2026 fərmver versiyasından əvvəlki sistemlərdə aşkarlanmış əmr inyeksiyası (command injection) zəifliyidir. Uzaqdan hücumçu /boafrm/formPinManageSetup interfeysindəki oldPIn parametrinə zərərli əmrlər daxil edərək ixtiyari əmrlərin icrasına nail ola bilər. İstifadəçilər dərhal cihazlarını ən son proqram təminatı ilə yeniləməli və idarəetmə interfeysinə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which D-Link devices are affected by CVE-2026-71952?
This vulnerability affects D-Link DWR-M961 devices with hardware version C1 running firmware versions prior to 1.1.5_C1_2026.
How can an attacker exploit CVE-2026-71952 to execute arbitrary commands?
A remote attacker can perform command injection by inserting malicious commands into the oldPIn parameter of the /boafrm/formPinManageSetup interface.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.