← Back to CVE search

CVE-2026-71957

Description

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

CVSS 9.8EPSS 0.594%Risk 1.03
View source
Published
2026-08-08 18:16:56
Last modified
2026-08-08 18:16:56
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H