CVE-2026-71954Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-09)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-08: 1Mentions · 2026-08-09: 2Technical Details · 2026-08-09: 208-0808-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-081
Disclosure1
2026-08-092
Disclosure2
Full discourse3 posts
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for D-Link DWR-M961 (CVE-2026-71954) https://vuldb.com/vuln/387202

    Post summary

    A new vulnerability, CVE-2026-71954, has been disclosed for the D-Link DWR-M961 router, with an increased severity score; further details are available via the cited link.

    00020157
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-71954 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3… https://www.cve.org/CVERecord?id=CVE-2026-71954

    Post summary

    CVE-2026-71954 details a command injection flaw in D-Link DWR‑M961 devices running firmware versions prior to 1.1.5_C1_202607071108, affecting the /boafrm/formL2tpv3 endpoint. No patch, exploit, or PoC information is included.

    000101.1K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-71954 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3… https://www.cve.org/CVERecord?id=CVE-2026-71954 ----- Traducción: CVE-2026-71954 Dis… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-71954, detailing a command injection vulnerability on specific D-Link devices, but provides no PoC, exploit code, or mitigation information.

    00000123
    98 followersView on X

Explore more