PatchSiren cyber security CVE debrief
CVE-2026-71953 D-Link Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.890Z and has not been modified since then. CVE-2026-71953 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formNtp interface, allowing remote attackers to inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. This vulnerability has a CVSS score of 9.3 and is considered critical. The debrief is based on official CVE and NVD records, as well as vendor and researcher references. To verify and mitigate this vulnerability, defenders should review the official advisory, check for affected product deployments, and apply firmware updates. They should also monitor for suspicious activity and restrict access to the /boafrm/formNtp interface.
- Vendor
- D-Link Corporation
- Product
- DWR-M961
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-08
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-08
- Advisory updated
- 2026-08-28
Who should care
Administrators and users of D-Link DWR-M961 devices, especially those with hardware version C1 and firmware version before 1.1.5_C1_202607071108, should be aware of this critical vulnerability and take immediate action to patch or mitigate the vulnerability. This includes reviewing the official advisory, applying firmware updates, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize patching affected devices.
Technical summary
CVE-2026-71953 is a critical command injection vulnerability in the /boafrm/formNtp interface of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. This vulnerability has a CVSS score of 9.3 and is considered critical. Administrators should prioritize patching affected devices and verify the integrity of their systems.
Defensive priority
Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 due to a critical command injection vulnerability.
Recommended defensive actions
- Patch D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108
- Verify and apply firmware updates
- Restrict access to the /boafrm/formNtp interface
- Monitor for suspicious activity
- Inventory affected devices
Evidence notes
The CVE-2026-71953 record indicates a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. Evidence is based on official CVE and NVD records, as well as vendor and researcher references. To verify and mitigate this vulnerability, defenders should review the official advisory, check for affected product deployments, and apply firmware updates. They should also monitor for suspicious activity and restrict access to the /boafrm/formNtp interface. The vulnerability allows remote attackers to inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. There may be limited information available about the vulnerability's impact and scope, and defenders should be cautious of potential exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71953 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71953
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71953 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71953
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.dlink.com/middle-east/en/products/dwr-m961-4g-ac1200-lte-router
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/d-link-dwr-m961-command-injection-via-boafrm-formntp
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.