PatchSiren cyber security CVE debrief
CVE-2026-71947 D-Link Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:47.983Z and has not been modified since then. The vulnerability affects D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. It is a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface that allows remote attackers to inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. Limited information is available about potential mitigations or patches. Defenders should verify the existence of affected devices in their environment and review the official advisory for specific guidance.
- Vendor
- D-Link Corporation
- Product
- DWR-M961
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-08
- Original CVE updated
- 2026-08-08
- Advisory published
- 2026-08-08
- Advisory updated
- 2026-08-08
Who should care
Administrators and users of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 should be aware of this critical vulnerability and take steps to mitigate it. This includes reviewing the official advisory, assessing their exposure, applying patches or mitigations, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should prioritize patching affected devices and consider compensating controls for unpatched devices.
Technical summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. The vulnerability allows for command execution with root privileges, making it a critical concern for administrators. It is recommended to review the official advisory and assess exposure to prioritize patching affected devices.
Defensive priority
Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 due to a critical command injection vulnerability.
Recommended defensive actions
- Apply firmware updates to D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108
- Restrict access to the /boafrm/formTracerouteDiagnosticRun interface
- Monitor for suspicious activity on affected devices
- Perform inventory checks to identify affected devices
- Consider compensating controls for unpatched devices
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide evidence of a command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. However, details about the affected scope and vendor remediation are limited. Defenders should verify the existence of affected devices in their environment, review the official advisory for specific guidance, and consider compensating controls for unpatched devices. The vulnerability allows remote attackers to inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. Limited information is available about potential mitigations or patches.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:47.983Z and has not been modified since then.