CVE-2026-71945 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 LtefotaUpgradeFibocom formLtefotaUpgradeFibocom fota_url command injection

SecurityVulns

A vulnerability categorized as very critical has been discovered in D-Link DWR-M961 up to 1.1.5_C1_202607071107. This vulnerability affects unknown code of the file /boafrm/formLtefotaUpgradeFibocom of the component LtefotaUpgradeFibocom. The manipulation of the argument fota_url results in command injection.

This vulnerability is reported as CVE-2026-71945. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More