CVE-2026-71950 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 SMS Management Interface /boafrm/formSmsManage action_value command injection
A vulnerability classified as very critical has been found in D-Link DWR-M961 up to 1.1.5_C1_202607071107. This affects an unknown function of the file /boafrm/formSmsManage of the component SMS Management Interface. The manipulation of the argument action_value leads to command injection.
This vulnerability is uniquely identified as CVE-2026-71950. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More