Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide mobile broadband connectivity to corporate and home networks. A buffer overflow vulnerability in the device's web management interface allows a remote attacker to send a specially crafted request that crashes the device or executes arbitrary commands, potentially compromising network security and availability.
Technical details
A buffer overflow vulnerability exists in the app.cgi component of the D-Link DWR-M961 (hardware revision C1, firmware 1.1.2_C1_202602110044), specifically in the handling of the netAcc.addlist[].name parameter. The vulnerability allows a remote attacker to write an overly long string to this field without proper bounds checking, causing a stack or heap overflow. An attacker can exploit this via network access to the device's web management interface to either cause a denial of service (device crash) or execute arbitrary commands with device privileges. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108.
Affected products
- D-Link DWR-M961 1.1.2_C1_202602110044 (hardware revision C1)
Timeline
- 2026-08-08: disclosed: CVE-2026-71957 published on NVD
- 2026-08-10: advisory: D-Link security announcement SAP10512 last updated
- 2026-07-07: patched: Firmware version 1.1.5_C1_202607071108 resolves the vulnerability