CVE-2026-71951: D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5C1202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEIvalue field, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961 (hardware version C1)to a version that resolves this vulnerability.Fixed in 1.1.5_C1_202607071108 - Compensating control
Restrict or otherwise limit access to the /boafrm/formIMEISetup interface on D-Link DWR-M961 (hardware version C1) until the device is upgraded, to reduce exposure to remote command injection via the IMEI_value field.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71951?
CVE-2026-71951 has a critical severity rating of 9.8.
How do I fix CVE-2026-71951?
To mitigate CVE-2026-71951, update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later.
What devices are affected by CVE-2026-71951?
CVE-2026-71951 affects D-Link DWR-M961 devices with hardware version C1 that are running firmware versions prior to 1.1.5_C1_202607071108.
What type of vulnerability is CVE-2026-71951?
CVE-2026-71951 is classified as an OS Command Injection vulnerability.
What can happen if CVE-2026-71951 is exploited?
If exploited, CVE-2026-71951 allows an attacker to execute arbitrary commands on the D-Link DWR-M961 device remotely.