What is CVE-2026-71957?
CVE-2026-71957 is a buffer overflow vulnerability in the app.cgi interface of D-Link DWR-M961 devices with hardware version C1 and specific software version. A remote attacker can execute arbitrary commands by writing an overly long string to the netAcc.addlist[].name field via a crafted request. Affected users should apply the security update from D-Link.
Azərbaycanca: CVE-2026-71957, D-Link DWR-M961 aparatının xüsusi hardware (C1) və proqram versiyasında app.cgi interfeysindəki buffer overflow zəifliyidir. Uzaqdan təcavüzkar xüsusi hazırlanmış sorğu ilə netAcc.addlist[].name sahəsinə həddindən artıq uzun sətir yazaraq ixtiyari əmrlər icra edə bilər. Təsirə məruz qalmış cihazlar üçün D-Link tərəfindən təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: D-Link
FAQ2
Which versions of the D-Link DWR-M961 are affected by CVE-2026-71957?
This vulnerability affects D-Link DWR-M961 devices with hardware version C1 running a specific software version.
How can users protect against CVE-2026-71957?
Affected users should apply the security update provided by D-Link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.