What is CVE-2026-71956?
A command injection vulnerability exists in the app.cgi interface of D-Link DWR-M961 devices (hardware version C1, software version 1.1.2_C1_202602110044). A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, achieving command execution with root privilege.
Azərbaycanca: D-Link DWR-M961 cihazlarında (hardware versiya C1, proqram versiyası 1.1.2_C1_202602110044) app.cgi interfeysində command injection zəifliyi aşkarlanıb. Uzaqdan hücum edən şəxs netDig.ping.dst sahəsinə zərərli əmrlər daxil edərək root səviyyəsində əmr icrasına nail ola bilər.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: D-Link
FAQ2
Which D-Link device and software version is affected by CVE-2026-71956?
This vulnerability affects D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044.
Where can an attacker inject commands in CVE-2026-71956 to gain root privilege?
A remote attacker can inject malicious commands into the netDig.ping.dst field in the app.cgi interface to achieve command execution with root privilege.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.