What is CVE-2026-71958?
A buffer overflow vulnerability exists in the quicksetup.cgi interface of D-Link DWR-M961 devices. A remote attacker can send overly long strings to the test4, ssid2, and username fields to execute arbitrary commands. Immediate firmware updates are recommended.
Azərbaycanca: D-Link DWR-M961 cihazlarının quicksetup.cgi interfeysində bufer daşması (buffer overflow) zəifliyi aşkarlanıb. Uzaqdan hücumçu xüsusi hazırlanmış sorğu ilə test4, ssid2 və username sahələrinə həddən artıq uzun sətir göndərərək əmr icra edə bilər. Dərhal cihazın proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: D-Link
FAQ2
Which interface of D-Link DWR-M961 devices does CVE-2026-71958 affect?
The vulnerability affects the quicksetup.cgi interface.
Which fields does an attacker send overly long strings to when exploiting CVE-2026-71958?
The attacker sends overly long strings to the test4, ssid2, and username fields.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.