CVE-2026-71949 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 USSD Setup /boafrm/formUSSDSetup ussdValue/selectMenuValue command injection

SecurityVulns

A vulnerability described as very critical has been identified in D-Link DWR-M961 up to 1.1.5_C1_202607071107. The impacted element is an unknown function of the file /boafrm/formUSSDSetup of the component USSD Setup. Executing a manipulation of the argument ussdValue/selectMenuValue can lead to command injection.

This vulnerability is handled as CVE-2026-71949. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More