CVE-2026-71957: D-Link Corporation Dwr-m961

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

Affected products

  • D-Link Corporation Dwr-m961: before 1.1.5_C1_202607071108 (fixed in 1.1.5_C1_202607071108)

Published 2026-08-08. Last modified 2026-08-31.