CVE-2026-71947 | D-Link DWR-M961 1.01.07 Traceroute Diagnostic Run formTracerouteDiagnosticRun host/ipVer command injection
A vulnerability labeled as very critical has been found in D-Link DWR-M961 1.01.07. Impacted is an unknown function of the file /boafrm/formTracerouteDiagnosticRun of the component Traceroute Diagnostic Run. Such manipulation of the argument host/ipVer leads to command injection.
This vulnerability is traded as CVE-2026-71947. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More