CVE-2026-71945 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 LtefotaUpgradeFibocom formLtefotaUpgradeFibocom fota_url command injection
A vulnerability categorized as very critical has been discovered in D-Link DWR-M961 up to 1.1.5_C1_202607071107. This vulnerability affects unknown code of the file /boafrm/formLtefotaUpgradeFibocom of the component LtefotaUpgradeFibocom. The manipulation of the argument fota_url results in command injection.
This vulnerability is reported as CVE-2026-71945. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More