CVE-2026-71955: D-Link DWR-M961 Command Injection via /boafrm/formWsc
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2C1202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.2_C1_202602110044 - Compensating control
Mitigate exploitation attempts against the vulnerable /boafrm/formWsc interface on D-Link DWR-M961 (hardware version C1, software version 1.1.2_C1_202602110044) by restricting network access to that endpoint (e.g., via firewall/WAF/ACL) to trusted sources only.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71955?
The severity of CVE-2026-71955 is critical with a score of 9.8.
How do I fix CVE-2026-71955?
To fix CVE-2026-71955, update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later.
What type of vulnerability is CVE-2026-71955?
CVE-2026-71955 is an OS Command Injection vulnerability.
Can CVE-2026-71955 be exploited remotely?
Yes, CVE-2026-71955 can be exploited remotely by an attacker.
Which devices are affected by CVE-2026-71955?
CVE-2026-71955 affects D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108.