CVE-2026-71954: D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5C1202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.5_C1_202607071108 - Compensating control
Restrict or otherwise prevent access to the /boafrm/formL2tpv3ConfigSetup interface from untrusted networks until devices are upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71954?
The severity of CVE-2026-71954 is critical with a score of 9.8.
How do I fix CVE-2026-71954?
To fix CVE-2026-71954, update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later.
What type of vulnerability is CVE-2026-71954?
CVE-2026-71954 is an OS Command Injection vulnerability that allows remote attackers to execute arbitrary commands.
What devices are affected by CVE-2026-71954?
D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 are affected.
Can CVE-2026-71954 be exploited remotely?
Yes, CVE-2026-71954 can be exploited remotely by injecting commands into the tunnelid and sessionid fields.