CVE-2026-1625: D-Link DWR-M961 SMS Message formSmsManage sub_4250E0 command injection
A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub4250E0 of the file /boafrm/formSmsManage of the component SMS Message. Performing a manipulation of the argument actionvalue results in command injection. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1625?
CVE-2026-1625 has a high severity rating due to its potential for command injection.
How do I fix CVE-2026-1625?
To fix CVE-2026-1625, update the D-Link DWR-M961 firmware to the latest version provided by D-Link.
What is CVE-2026-1625?
CVE-2026-1625 is a command injection vulnerability in the SMS Message component of the D-Link DWR-M961 router.
Who is affected by CVE-2026-1625?
Users of the D-Link DWR-M961 router running firmware version 1.1.47 are affected by CVE-2026-1625.
What are the consequences of CVE-2026-1625?
Exploitation of CVE-2026-1625 could allow an attacker to execute arbitrary commands on the D-Link DWR-M961 device.