CVE-2026-71957 Details
Description
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
A buffer overflow vulnerability has been identified in the D-Link DWR-M961 router, specifically in devices with hardware version C1 and software version 1.1.2_C1_202602110044. The vulnerability resides in the app.cgi interface, where a remote attacker can send an overly long string to the netAcc.addlist[].name field. This could lead to the execution of arbitrary commands or cause the device to crash.
Users with a DWR-M961 hardware revision C1 should update to firmware version 1.1.5_C1_202607071108. After updating, verify that the device's administration interface displays the new firmware version. The update is available as a direct download from the D-Link support resource.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 8, 2026CISA-ADP
Assessed Aug 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10512 | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.dlink.com/middle-east/en/products/dwr-m961-4g-ac1200-lte-router | [email protected] | ProductVendor |
| https://www.vulncheck.com/advisories/d-link-dwr-m961-buffer-overflow-via-app-cgi | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| D-Link DWR-M961 | <= 1.1.2_C1_202602110044 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | CISA-ADP |
| Aug 8, 2026 | New CVE Received | [email protected] |
Volerion