CVE-2026-71950 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 SMS Management Interface /boafrm/formSmsManage action_value command injection

SecurityVulns

A vulnerability classified as very critical has been found in D-Link DWR-M961 up to 1.1.5_C1_202607071107. This affects an unknown function of the file /boafrm/formSmsManage of the component SMS Management Interface. The manipulation of the argument action_value leads to command injection.

This vulnerability is uniquely identified as CVE-2026-71950. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More