What is CVE-2026-71955?
CVE-2026-71955 is a command injection vulnerability in the /boafrm/formWsc interface of D-Link DWR-M961 devices. A remote attacker can execute arbitrary commands via the localPin, targetAPSsid, peerPin, and peerRptPin fields. Affected users should apply the vendor's security patch immediately.
Azərbaycanca: CVE-2026-71955 D-Link DWR-M961 cihazlarında /boafrm/formWsc interfeysində command injection zəifliyidir. Uzaqdan hücumçu localPin, targetAPSsid, peerPin və peerRptPin sahələrinə ixtiyari əmrlər daxil edərək sistemi ələ keçirə bilər. Təsirlənən cihazlar üçün istehsalçı tərəfindən təhlükəsizlik yeniləməsinin tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: D-Link
FAQ2
Which manufacturer's devices are affected by CVE-2026-71955, and in which interface does the vulnerability reside?
CVE-2026-71955 is a command injection vulnerability found in the /boafrm/formWsc interface of D-Link DWR-M961 devices.
How can an attacker exploit the CVE-2026-71955 vulnerability to compromise the system?
A remote attacker can exploit CVE-2026-71955 by injecting arbitrary commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.