CVE-2026-71957: D-Link DWR-M961 Buffer Overflow via app.cgi
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2C1202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.2_C1_202602110044
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71957?
CVE-2026-71957 has a critical severity rating of 9.8.
How do I fix CVE-2026-71957?
To mitigate CVE-2026-71957, update your D-Link DWR-M961 device to the latest firmware version provided by D-Link.
What type of vulnerability is CVE-2026-71957?
CVE-2026-71957 is categorized as a Buffer Overflow vulnerability.
Which D-Link devices are affected by CVE-2026-71957?
CVE-2026-71957 affects D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044.
What can an attacker do with the CVE-2026-71957 vulnerability?
An attacker can execute arbitrary commands on the affected D-Link DWR-M961 devices by exploiting the buffer overflow in the app.cgi interface.