CVE-2026-71952: D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5C1202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.5_C1_202607071108
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71952?
CVE-2026-71952 has a severity rating of critical with a score of 9.8.
How do I fix CVE-2026-71952?
To mitigate CVE-2026-71952, update your D-Link DWR-M961 device to firmware version 1.1.5_C1_202607071108 or later.
What type of vulnerability is CVE-2026-71952?
CVE-2026-71952 is classified as an OS Command Injection vulnerability.
What can an attacker do with CVE-2026-71952?
An attacker exploiting CVE-2026-71952 can inject arbitrary commands, leading to potential remote code execution.
Which devices are affected by CVE-2026-71952?
Only the D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 are affected.