CVE-2026-71948 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 formDebugDiagnosticRun interface host command injection
A vulnerability marked as very critical has been reported in D-Link DWR-M961 up to 1.1.5_C1_202607071107. The affected element is an unknown function of the file /boafrm/formDebugDiagnosticRun of the component formDebugDiagnosticRun interface. Performing a manipulation of the argument host results in command injection.
This vulnerability is known as CVE-2026-71948. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More