What is CVE-2026-71953?
CVE-2026-71953 is a command injection vulnerability found in D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_2026. A remote attacker can inject arbitrary commands into the ntpServerIp1 parameter of the /boafrm/formNtp interface, leading to remote command execution on the affected device.
Azərbaycanca: CVE-2026-71953, D-Link DWR-M961 cihazının hardware versiyası C1 olan modellərində, 1.1.5_C1_2026-dən əvvəlki firmware versiyalarında aşkarlanmış əmr inyeksiyası (command injection) zəifliyidir. Uzaqdan hücum edən şəxs /boafrm/formNtp interfeysindəki ntpServerIp1 sahəsinə zərərli əmrlər yeridərək, cihazda ixtiyari əmrlərin icrasına nail ola bilər.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which D-Link device model is affected by CVE-2026-71953?
This vulnerability affects D-Link DWR-M961 devices with hardware version C1.
Where can an attacker inject commands when exploiting CVE-2026-71953?
An attacker can inject malicious commands into the ntpServerIp1 parameter of the /boafrm/formNtp interface.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.