PatchSiren

D-Link Corporation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71957

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T18:16:56.647Z and has not been modified since then. D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field an [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71955

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.250Z and has not been modified since then. D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71954

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:49.097Z and has not been modified since then. D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious command [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71953

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.890Z and has not been modified since then. CVE-2026-71953 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formNtp interface, allowing remote attack [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71952

CVE-2026-71952 is a critical command injection vulnerability affecting D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formPinManageSetup interface, allowing remote attackers to inject malicious commands into the oldPin field, leading to command execution with root privileges. This vulnerability has a CVSS score of [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71947

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:47.983Z and has not been modified since then. The vulnerability affects D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. It is a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface that allows remote attacke [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71946

CVE-2026-71946 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formPingDiagnosticRun interface, allowing remote attackers to inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. This vulnerability has a CVSS sc [truncated]

CRITICAL D-Link Corporation CVE published 2026-08-08

CVE-2026-71944

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:47.550Z and has not been modified since then. CVE-2026-71944 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formLtefotaUpgradeQuectel interface, allo [truncated]

MEDIUM D-Link Corporation CVE published 2026-05-28

CVE-2026-4377

CVE-2026-4377 documents a medium-severity weakness in D-Link DWR-X1820 routers where default administrative passwords are deterministically generated from the device's IMEI number. The vulnerability, published 2026-05-28, enables attackers with knowledge of the generation algorithm and physical access to the device (or its IMEI) to derive credentials without brute-force effort. No CISA KEV listing or know [truncated]