CVE-2026-71946 | D-Link DWR-M961 1.01.07 formPingDiagnosticRun host command injection
A vulnerability identified as very critical has been detected in D-Link DWR-M961 1.01.07. This issue affects some unknown processing of the file /boafrm/formPingDiagnosticRun of the component formPingDiagnosticRun. This manipulation of the argument host causes command injection.
This vulnerability appears as CVE-2026-71946. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More