CVE-2026-71949: D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5C1202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.5_C1_202607071108
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71949?
CVE-2026-71949 has a critical severity rating of 9.8.
How do I fix CVE-2026-71949?
To fix CVE-2026-71949, update the D-Link DWR-M961 to firmware version 1.1.5_C1_202607071108 or later.
What type of vulnerability is CVE-2026-71949?
CVE-2026-71949 is classified as an OS Command Injection vulnerability.
What are the affected devices for CVE-2026-71949?
D-Link DWR-M961 devices with hardware version C1 and firmware before version 1.1.5_C1_202607071108 are affected by CVE-2026-71949.
Can CVE-2026-71949 be exploited remotely?
Yes, CVE-2026-71949 can be exploited remotely, allowing attackers to inject malicious commands.