AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71957

CRITICAL · CVSS 9.8 EPSS 0.59%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 are vulnerable to a buffer overflow in the app.cgi interface, allowing remote attackers to execute arbitrary commands or crash the device by sending a specially crafted payload. Organizations using these devices should prioritize patching this critical vulnerability to prevent potential exploitation and ensure network security. Immediate action is recommended for environments where these devices are deployed.

CVE
CVE-2026-71957
Severity
CRITICAL
CVSS
9.8
EPSS
0.59%

Original NVD Description

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.