CVE-2026-71944 | D-Link DWR-M961 up to 1.1.5_C1_202607071107 LTE Firmware Upgrade Interface formLtefotaUpgradeQuectel fota_url command injection

SecurityVulns

A vulnerability was found in D-Link DWR-M961 up to 1.1.5_C1_202607071107. It has been rated as very critical. This affects an unknown part of the file /boafrm/formLtefotaUpgradeQuectel of the component LTE Firmware Upgrade Interface. The manipulation of the argument fota_url leads to command injection.

This vulnerability is documented as CVE-2026-71944. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More