Currently free during beta - premium features coming soon. Subscribe now to lock in early access.

CVE-2026-71958 (CVSS 9.8) — D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly

CVE Vulnerabilities & CVEs · · nvd

AI Analysis

A new critical vulnerability, CVE-2026-71958, has been published with a CVSS score of 9.8. It affects D-Link DWR-M961 routers with hardware version C1 and software version 1.1.2_C1_202602110044. The flaw is a buffer overflow in the quicksetup.cgi interface, allowing a remote attacker to send overly long input and potentially execute arbitrary code or crash the device. Because the vulnerability is remotely exploitable without authentication, it poses a severe risk to network integrity and data confidentiality.

Organizations affected include any entity using this specific D-Link router model, particularly small and medium businesses, branch offices, or remote sites that rely on DWR-M961 devices for cellular or broadband connectivity. Sectors such as retail, logistics, and telecommunications are common users of such equipment. If these devices are exposed to the internet or untrusted networks, the attack surface is significant, potentially enabling lateral movement or disruption of critical communications.

Compliance teams should immediately verify whether any D-Link DWR-M961 devices are in use and check their firmware versions. If affected, isolate the devices from external access, apply any vendor patch or workaround as soon as available, and monitor vendor advisories. Additionally, document this vulnerability in your risk register and update incident response plans, as this may trigger breach reporting obligations under GDPR or sector-specific regulations if exploitation is suspected. Prioritize patching and network segmentation to mitigate exposure.

Get notified about CVE changes

Subscribe to our free weekly digest covering 24 compliance frameworks.