CVE-2026-71950: D-Link DWR-M961 Command Injection via /boafrm/formSmsManage
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5C1202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the actionvalue field, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.5_C1_202607071108 - Configuration
Harden or restrict the /boafrm/formSmsManage interface so that arbitrary content in the action_value field cannot be used to trigger command execution (devices are affected when firmware is before 1.1.5_C1_202607071108 on hardware version C1).
D-Link DWR-M961 /boafrm/formSmsManage Action value handling = block/disable processing of action_value that can contain command injection payloads
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71950?
The severity of CVE-2026-71950 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-71950?
To fix CVE-2026-71950, update the D-Link DWR-M961 device to firmware version 1.1.5_C1_202607071108 or later.
What kind of systems are affected by CVE-2026-71950?
CVE-2026-71950 affects D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108.
What type of vulnerability is CVE-2026-71950?
CVE-2026-71950 is a command injection vulnerability that allows remote attackers to execute arbitrary commands.
Can CVE-2026-71950 be exploited remotely?
Yes, CVE-2026-71950 can be exploited remotely due to its nature of allowing command injection via the /boafrm/formSmsManage interface.