AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71958

CRITICAL · CVSS 9.8 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 are vulnerable to a buffer overflow in the quicksetup.cgi interface, allowing remote attackers to execute arbitrary commands or crash the device by sending specially crafted input. Organizations using these devices should prioritize patching or mitigating this vulnerability due to its critical severity and potential for significant impact on network security. Immediate action is essential to prevent unauthorized access and maintain device integrity.

CVE
CVE-2026-71958
Severity
CRITICAL
CVSS
9.8
EPSS
0.56%

Original NVD Description

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.