D-Link DWR-M961 routers, hardware version C1, were found to contain five critical vulnerabilities that allow remote, unauthenticated attackers to execute arbitrary commands as root or crash the device. The issues affect firmware versions earlier than 1.1.5_C1_202607071108 and include three command injection flaws—CVE-2026-71944 in /boafrm/formLtefotaUpgradeQuectel via fota_url, CVE-2026-71955 in /boafrm/formWsc via fields including localPin, targetAPSsid, peerPin, and peerRptPin, and CVE-2026-71956 in app.cgi via netDig.ping.dst—as well as two buffer overflows: CVE-2026-71957 in app.cgi via netAcc.addlist[].name and CVE-2026-71958 in quicksetup.cgi via test4, ssid2, and username.
All five bugs carry a CVSS 3.1 score of 9.8 and were classified under CWE-78 for command injection or CWE-120 for buffer overflow, reflecting high impact on confidentiality, integrity, and availability. Public reporting credited researchers Jincheng Wang, Le Yu, and Xiapu Luo with the discoveries, while D-Link released firmware 1.1.5_C1_202607071108 to address the flaws. Reporting at the time of disclosure said no active exploitation had been observed, and the vulnerabilities were also highlighted by regional CERT reporting on D-Link products.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A ThreatAft article published on August 9, 2026 summarized five critical D-Link DWR-M961 vulnerabilities, credited their discovery to Jincheng Wang, Le Yu, and Xiapu Luo, and stated that no active exploitation had been reported at the time of publication. The report grouped CVE-2026-71944, CVE-2026-71955, CVE-2026-71956, CVE-2026-71957, and CVE-2026-71958 as a coordinated disclosure affecting firmware prior to 1.1.5_C1_202607071108.
On August 8, 2026, CVE-2026-71955 was newly received for a command injection flaw in /boafrm/formWsc on D-Link DWR-M961 C1 devices. The CVE record was also modified that day to expand the affected version range and broaden the injectable fields from a narrower description to include localPin, targetAPSsid, peerPin, and peerRptPin.
On August 8, 2026, CVE-2026-71958 was disclosed for a buffer overflow in quicksetup.cgi on D-Link DWR-M961 C1 devices. Remote unauthenticated attackers can use overly long values in test4, ssid2, or username to execute commands or crash the router.
On August 8, 2026, CVE-2026-71957 was received for a buffer overflow in app.cgi affecting D-Link DWR-M961 C1 devices. An attacker can send an overly long value to netAcc.addlist[].name to achieve command execution or crash the device.
On August 8, 2026, CVE-2026-71956 was newly received for a command injection vulnerability in the DWR-M961 app.cgi interface. The flaw lets remote attackers inject commands through the netDig.ping.dst field and execute them with root privileges.
On August 8, 2026, CVE-2026-71944 was newly received for a command injection flaw in /boafrm/formLtefotaUpgradeQuectel on D-Link DWR-M961 C1 devices. The issue allows remote attackers to inject commands via the fota_url field and gain root-level execution.
D-Link released firmware version 1.1.5_C1_202607071108 as the fix for multiple critical vulnerabilities affecting DWR-M961 hardware version C1. The vulnerable range is described as versions earlier than this firmware release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourcethreataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.