CVE-2026-71958

D-Link · DWR-M961

D-Link DWR-M961 routers contain a buffer overflow vulnerability in the quicksetup.cgi interface, allowing unauthenticated attackers to execute arbitrary code via crafted input.

Executive summary

An unauthenticated remote buffer overflow vulnerability in D-Link DWR-M961 routers allows attackers to achieve arbitrary code execution via the quicksetup.cgi interface.

Vulnerability

The vulnerability is a buffer overflow (CWE-120) within the quicksetup.cgi interface. An unauthenticated attacker can submit overly long strings to the test4, ssid2, or username fields to trigger an overflow and execute arbitrary commands.

Business impact

The CVSS score of 9.8 underscores the severe impact of this vulnerability, which allows an attacker to bypass authentication and execute code on the device. This could lead to a total loss of confidentiality, integrity, and availability for the affected network segment.

Remediation

Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later to resolve the vulnerability.

Proactive Monitoring: Monitor for suspicious web requests targeting the quicksetup.cgi path in the device logs.

Compensating Controls: Limit access to the administrative web interface to trusted management networks to minimize the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given that this is a critical remote code execution flaw, immediate patching is required. Organizations should ensure all affected D-Link DWR-M961 devices are updated to the latest firmware to eliminate this security risk.