CVE-2026-71958: D-Link DWR-M961 Buffer Overflow via quicksetup.cgi
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2C1202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.2_C1_202602110044
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71958?
CVE-2026-71958 has a critical severity rating of 9.8.
How do I fix CVE-2026-71958?
To mitigate CVE-2026-71958, upgrade the D-Link DWR-M961 to the latest firmware version provided by D-Link.
What devices are affected by CVE-2026-71958?
CVE-2026-71958 affects D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044.
What type of vulnerability is CVE-2026-71958?
CVE-2026-71958 is a buffer overflow vulnerability.
Can CVE-2026-71958 allow remote code execution?
Yes, CVE-2026-71958 can allow a remote attacker to execute arbitrary commands on the device.