PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71947 D-Link Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:47.983Z and has not been modified since then. The vulnerability affects D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. It is a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface that allows remote attackers to inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. Limited information is available about potential mitigations or patches. Defenders should verify the existence of affected devices in their environment and review the official advisory for specific guidance.

Vendor
D-Link Corporation
Product
DWR-M961
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-08
Original CVE updated
2026-08-08
Advisory published
2026-08-08
Advisory updated
2026-08-08

Who should care

Administrators and users of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 should be aware of this critical vulnerability and take steps to mitigate it. This includes reviewing the official advisory, assessing their exposure, applying patches or mitigations, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should prioritize patching affected devices and consider compensating controls for unpatched devices.

Technical summary

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. The vulnerability allows for command execution with root privileges, making it a critical concern for administrators. It is recommended to review the official advisory and assess exposure to prioritize patching affected devices.

Defensive priority

Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 due to a critical command injection vulnerability.

Recommended defensive actions

  • Apply firmware updates to D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108
  • Restrict access to the /boafrm/formTracerouteDiagnosticRun interface
  • Monitor for suspicious activity on affected devices
  • Perform inventory checks to identify affected devices
  • Consider compensating controls for unpatched devices
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide evidence of a command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. However, details about the affected scope and vendor remediation are limited. Defenders should verify the existence of affected devices in their environment, review the official advisory for specific guidance, and consider compensating controls for unpatched devices. The vulnerability allows remote attackers to inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. Limited information is available about potential mitigations or patches.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:47.983Z and has not been modified since then.