PT-2026-69219 · D Link · Dwr-M961
CVE-2026-71953
·
Published
2026-08-08
·
Updated
2026-08-28
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-M961 hardware version C1 versions prior to 1.1.5 C1 202607071108
Description
A command injection issue exists in the '/boafrm/formNtp' endpoint. A remote attacker can inject arbitrary malicious commands through the
ntpServerIp1 field, allowing for command execution with root privileges.Recommendations
Update to firmware version 1.1.5 C1 202607071108 or later.
Avoid using the
ntpServerIp1 field in the '/boafrm/formNtp' interface until the update is applied.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dwr-M961