PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71954 D-Link Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.097Z and has not been modified since then. D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges. Administrators and users of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 should be aware of this critical vulnerability and take steps to mitigate it. Additionally, security teams and vulnerability management teams should review the official CVE record and NVD entry to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. The vulnerability has a CVSS score of 9.3 and is considered critical.

Vendor
D-Link Corporation
Product
DWR-M961
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-08
Original CVE updated
2026-08-08
Advisory published
2026-08-08
Advisory updated
2026-08-08

Who should care

Administrators and users of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 should be aware of this critical vulnerability and take steps to mitigate it. Additionally, security teams and vulnerability management teams should review the official CVE record and NVD entry to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges. The vulnerability is due to insufficient input validation and sanitization of user-supplied input. The CVE record and NVD entry provide evidence of a command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. However, details about the affected scope and vendor remediation are limited. To verify and mitigate this vulnerability, defenders should review the official CVE record and NVD entry, check for any available firmware updates, and monitor for suspicious activity on affected devices.

Defensive priority

Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 due to a critical command injection vulnerability.

Recommended defensive actions

  • Apply firmware updates to D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108
  • Restrict access to the /boafrm/formL2tpv3ConfigSetup interface
  • Monitor for suspicious activity on affected devices
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide evidence of a command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. However, details about the affected scope and vendor remediation are limited. To verify and mitigate this vulnerability, defenders should review the official CVE record and NVD entry, check for any available firmware updates, and monitor for suspicious activity on affected devices. Additionally, defenders should be aware of the potential for remote attackers to inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.097Z and has not been modified since then.