What is CVE-2026-71954?
CVE-2026-71954 is a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface of D-Link DWR-M961 devices (hardware version C1) with firmware prior to 1.1.5_C1_202607071108. A remote attacker can inject arbitrary commands via the tunnelid and sessionid fields, potentially gaining control of the device. Users should update to the latest firmware immediately.
Azərbaycanca: CVE-2026-71954 D-Link DWR-M961 (hardware C1) cihazlarında 1.1.5_C1_202607071108-dən əvvəlki firmware versiyalarında, /boafrm/formL2tpv3ConfigSetup interfeysində command injection zəifliyidir. Uzaqdan hücumçu tunnelid və sessionid sahələrinə arbitrari əmrlər əlavə edərək cihazda əmr icra edə bilər. Təsirlənən cihazları son firmware versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which D-Link device models are affected by CVE-2026-71954?
CVE-2026-71954 affects D-Link DWR-M961 devices (hardware version C1) with firmware prior to 1.1.5_C1_202607071108.
How can I protect against CVE-2026-71954?
It is recommended to update the firmware of affected devices to the latest version to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.