CVE-2026-71944Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-08); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1Mentions · 2026-08-10: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 1Technical Details · 2026-08-10: 108-0808-0908-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-081
Disclosure1
2026-08-091
Patch1
2026-08-101
Disclosure1
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Command Injection & Buffer Overflow vulnerabilities in #DLink DWR-M961. CVE-2026-71944 through CVE-2026-71958. CVSS: 9.8. Unauthenticated remote attackers can inject commands for root-level execution, or overflow buffers. #Patch #Patch #Patch

    Post summary

    The post warns of severe command injection and buffer overflow flaws in the DLink DWR‑M961 (CVE‑2026‑71944‑71958) with a high CVSS score, but it offers no PoC, exploit details, or specific patch information.

    01000398
    7.2K followersView on X
  • ThreatAft@ThreatAft
    Patch

    🔐🚨 D-Link DWR-M961 4-CVE Bundle — ALL CVSS 9.8 CVE-2026-71944/71955/71956: Command Injection CVE-2026-71957/71958: Buffer Overflow Patch to 1.1.5_C1_202607071108 NOW. → http://threataft.com/articles/d-link-dwr-m961-4-cve-bundle #cybersecurity #infosec #DLink #RouterSecurity #ThreatIntel

    Post summary

    The post announces four high‑severity CVEs affecting a D-Link router, describes their technical nature, and urges users to apply the newly released patch.

    0000061
    36 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    📡 D-Link router hit by a massive batch of critical vulnerabilities A batch of 15 CVEs — CVE-2026-71944 through CVE-2026-71958 — was published for the D-Link DWR-M961 on August 8. The flaws include multiple command-injection bugs and buffer overflows. Several carry a CVSS 9.8 Critical rating. 🔎 Source: Rapid7 / CVE / VulnCheck. #DLink #RouterSecurity #CVE #CyberSecurity #IoTSecurity

    Post summary

    Rapid7 disclosed 15 critical CVEs (CVE-2026-71944 to CVE-2026-71958) affecting D-Link DWR‑M961, highlighting command‑injection and buffer overflow flaws with CVSS 9.8 ratings.

    0000050
    34 followersView on X

Explore more