PatchSiren cyber security CVE debrief
CVE-2026-71953 D-Link Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.890Z and has not been modified since then. CVE-2026-71953 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formNtp interface, allowing remote attackers to inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. This vulnerability has a CVSS score of 9.3 and is considered critical. The debrief is based on official CVE and NVD records, as well as vendor and researcher references. To verify and mitigate this vulnerability, defenders should review the official advisory, check for affected product deployments, and apply firmware updates. They should also monitor for suspicious activity and restrict access to the /boafrm/formNtp interface.
- Vendor
- D-Link Corporation
- Product
- DWR-M961
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-08
- Original CVE updated
- 2026-08-08
- Advisory published
- 2026-08-08
- Advisory updated
- 2026-08-08
Who should care
Administrators and users of D-Link DWR-M961 devices, especially those with hardware version C1 and firmware version before 1.1.5_C1_202607071108, should be aware of this critical vulnerability and take immediate action to patch or mitigate the vulnerability. This includes reviewing the official advisory, applying firmware updates, and monitoring for suspicious activity. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize patching affected devices.
Technical summary
CVE-2026-71953 is a critical command injection vulnerability in the /boafrm/formNtp interface of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. This vulnerability has a CVSS score of 9.3 and is considered critical. Administrators should prioritize patching affected devices and verify the integrity of their systems.
Defensive priority
Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 due to a critical command injection vulnerability.
Recommended defensive actions
- Patch D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108
- Verify and apply firmware updates
- Restrict access to the /boafrm/formNtp interface
- Monitor for suspicious activity
- Inventory affected devices
Evidence notes
The CVE-2026-71953 record indicates a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. Evidence is based on official CVE and NVD records, as well as vendor and researcher references. To verify and mitigate this vulnerability, defenders should review the official advisory, check for affected product deployments, and apply firmware updates. They should also monitor for suspicious activity and restrict access to the /boafrm/formNtp interface. The vulnerability allows remote attackers to inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. There may be limited information available about the vulnerability's impact and scope, and defenders should be cautious of potential exploitation.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.890Z and has not been modified since then.