PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71955 D-Link Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.250Z and has not been modified since then. D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. The vulnerability allows for command execution with root privileges, making it critical for administrators to prioritize patching. The CVE record and NVD entry provide details on the vulnerability, but additional context is needed for a comprehensive understanding. Evidence is limited to CVE and NVD entries, so defenders should focus on patching and compensating controls. Administrators should verify the affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations.

Vendor
D-Link Corporation
Product
DWR-M961
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-08
Original CVE updated
2026-08-08
Advisory published
2026-08-08
Advisory updated
2026-08-08

Who should care

Administrators and users of D-Link DWR-M961 devices, as well as organizations that rely on these devices for network connectivity, should prioritize patching and take additional measures to protect against this vulnerability. This includes reviewing compensating controls, monitoring for suspicious activity, and conducting regular vulnerability assessments. The vulnerability's critical severity and potential for command execution with root privileges make it essential for affected parties to take immediate action.

Technical summary

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. The vulnerability allows for command execution with root privileges, making it critical for administrators to prioritize patching. The CVE record and NVD entry provide details on the vulnerability, but additional context is needed for a comprehensive understanding.

Defensive priority

Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 due to a critical command injection vulnerability.

Recommended defensive actions

  • Apply patches or updates provided by the vendor
  • Restrict access to the /boafrm/formWsc interface
  • Monitor for suspicious activity
  • Conduct regular vulnerability assessments
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide evidence of a command injection vulnerability in D-Link DWR-M961 devices. However, details about the vendor's response and affected scope are limited. Administrators should verify the affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations. The vulnerability allows remote attackers to inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. Evidence is limited to CVE and NVD entries, so defenders should focus on patching and compensating controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.250Z and has not been modified since then.