CVE-2026-71957
D-Link · DWR-M961
D-Link DWR-M961 routers are susceptible to a buffer overflow in the app.cgi interface, which allows unauthenticated remote attackers to execute arbitrary commands or crash the device.
Executive summary
A critical buffer overflow vulnerability in D-Link DWR-M961 routers permits unauthenticated remote code execution via the app.cgi interface.
Vulnerability
This is a classic buffer overflow (CWE-120) in the app.cgi interface. By sending an excessively long string to the netAcc.addlist[].name field, an unauthenticated attacker can overwrite memory to execute arbitrary code or trigger a system crash.
Business impact
With a CVSS score of 9.8, this vulnerability represents a critical risk to network security. Successful exploitation grants an attacker the ability to execute arbitrary code, potentially leading to full control over the router, data exfiltration, or complete network disruption.
Remediation
Immediate Action: Apply the firmware update to version 1.1.5_C1_202607071108 or newer to address the underlying memory safety issue.
Proactive Monitoring: Review system logs for signs of repeated crashes or abnormal process termination, which may indicate attempted exploitation.
Compensating Controls: Implement strict ingress filtering at the network perimeter to prevent unauthorized access to the router's management web interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate remediation. Administrators should verify the current firmware version and apply the vendor-provided patch as soon as possible to prevent potential remote exploitation.