CVE-2026-71958
D-Link · DWR-M961
D-Link DWR-M961 routers contain a buffer overflow vulnerability in the quicksetup.cgi interface, allowing unauthenticated attackers to execute arbitrary code via crafted input.
Executive summary
An unauthenticated remote buffer overflow vulnerability in D-Link DWR-M961 routers allows attackers to achieve arbitrary code execution via the quicksetup.cgi interface.
Vulnerability
The vulnerability is a buffer overflow (CWE-120) within the quicksetup.cgi interface. An unauthenticated attacker can submit overly long strings to the test4, ssid2, or username fields to trigger an overflow and execute arbitrary commands.
Business impact
The CVSS score of 9.8 underscores the severe impact of this vulnerability, which allows an attacker to bypass authentication and execute code on the device. This could lead to a total loss of confidentiality, integrity, and availability for the affected network segment.
Remediation
Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later to resolve the vulnerability.
Proactive Monitoring: Monitor for suspicious web requests targeting the quicksetup.cgi path in the device logs.
Compensating Controls: Limit access to the administrative web interface to trusted management networks to minimize the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given that this is a critical remote code execution flaw, immediate patching is required. Organizations should ensure all affected D-Link DWR-M961 devices are updated to the latest firmware to eliminate this security risk.