CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-71957 — Critical vulnerability brief

August 8, 2026CVSS 9.3

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

CVSS base score: 9.3 / 10

View NVD record