PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71951 D-Link CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.570Z and has not been modified since then. CVE-2026-71951 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formIMEISetup interface, allowing remote attackers to inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges. The vulnerability has a CVSS score of 9.3 and is considered critical. Limited evidence is available about affected scope and vendor remediation efforts. To verify and assess potential exposure, defenders should review device inventories, check for firmware updates, and monitor for suspicious activity. Additional information from D-Link or other sources may be necessary to fully understand the vulnerability's impact.

Vendor
D-Link
Product
DWR-M961
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-08
Original CVE updated
2026-08-08
Advisory published
2026-08-08
Advisory updated
2026-08-08

Who should care

Administrators and security teams responsible for D-Link DWR-M961 devices, particularly those with hardware version C1 and firmware version before 1.1.5_C1_202607071108, should be aware of this critical vulnerability and take immediate action to patch or mitigate it. Additionally, operators, platform administrators, and vulnerability management teams should review their environments for potentially affected devices and prioritize remediation efforts.

Technical summary

CVE-2026-71951 is a critical command injection vulnerability in the /boafrm/formIMEISetup interface of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges. The vulnerability has a CVSS score of 9.3 and is considered critical. It is essential for administrators to prioritize patching affected devices and implement additional security measures to mitigate potential risks.

Defensive priority

Administrators should prioritize patching D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 due to a critical command injection vulnerability.

Recommended defensive actions

  • Apply firmware updates to D-Link DWR-M961 devices with hardware version C1 to version 1.1.5_C1_202607071108 or later
  • Restrict access to the /boafrm/formIMEISetup interface
  • Monitor for suspicious activity on affected devices
  • Perform inventory checks to identify potentially vulnerable devices
  • Consider implementing compensating controls for unpatched devices
  • Review device configurations to ensure secure settings
  • Track and verify patch deployment across the organization

Evidence notes

The CVE-2026-71951 record indicates a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. Evidence is based on official CVE and NVD records, as well as references from D-Link and VulnCheck. However, details about affected scope and vendor remediation efforts are limited. To verify and assess potential exposure, defenders should review device inventories, check for firmware updates, and monitor for suspicious activity. Additional information from D-Link or other sources may be necessary to fully understand the vulnerability's impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.570Z and has not been modified since then.