PatchSiren cyber security CVE debrief
CVE-2026-71955 D-Link Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.250Z and has not been modified since then. D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. The vulnerability allows for command execution with root privileges, making it critical for administrators to prioritize patching. The CVE record and NVD entry provide details on the vulnerability, but additional context is needed for a comprehensive understanding. Evidence is limited to CVE and NVD entries, so defenders should focus on patching and compensating controls. Administrators should verify the affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations.
- Vendor
- D-Link Corporation
- Product
- DWR-M961
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-08
- Original CVE updated
- 2026-08-08
- Advisory published
- 2026-08-08
- Advisory updated
- 2026-08-08
Who should care
Administrators and users of D-Link DWR-M961 devices, as well as organizations that rely on these devices for network connectivity, should prioritize patching and take additional measures to protect against this vulnerability. This includes reviewing compensating controls, monitoring for suspicious activity, and conducting regular vulnerability assessments. The vulnerability's critical severity and potential for command execution with root privileges make it essential for affected parties to take immediate action.
Technical summary
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. The vulnerability allows for command execution with root privileges, making it critical for administrators to prioritize patching. The CVE record and NVD entry provide details on the vulnerability, but additional context is needed for a comprehensive understanding.
Defensive priority
Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 due to a critical command injection vulnerability.
Recommended defensive actions
- Apply patches or updates provided by the vendor
- Restrict access to the /boafrm/formWsc interface
- Monitor for suspicious activity
- Conduct regular vulnerability assessments
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide evidence of a command injection vulnerability in D-Link DWR-M961 devices. However, details about the vendor's response and affected scope are limited. Administrators should verify the affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations. The vulnerability allows remote attackers to inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. Evidence is limited to CVE and NVD entries, so defenders should focus on patching and compensating controls.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.250Z and has not been modified since then.