Description
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The D-Link DWR‑M961 router contains a buffer overflow in the quicksetup.cgi interface. An attacker who can send HTTP requests to the device can supply overly long strings to the test4, ssid2, and username fields, causing the firmware to overwrite memory and execute arbitrary commands. This enables remote attackers to take full control of the router, exfiltrate data, or use it as a foothold for wider network attacks.

Affected Systems

Affected devices are D-Link DWR‑M961 routers with hardware version C1 and software version 1.1.2_C1_202602110044. No other versions are listed.

Risk and Exploitability

The CVSS score is 9.3, indicating critical severity. No EPSS score is available, so the exact exploitation probability cannot be quantified. The vulnerability is not in the CISA KEV catalog. Because the flaw is triggered by external HTTP requests, an attacker who can reach the device over the internet or an internal network can exploit it, making the attack vector remote.

Generated by OpenCVE AI on August 8, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by D‑Link that addresses the quicksetup.cgi buffer overflow.
  • Restrict management access to the device by blocking external IPs or placing the router behind a firewall that allows only trusted internal networks to reach the CGI interface.
  • If the quicksetup interface is not required, disable it or limit its use to secure local connections.

Generated by OpenCVE AI on August 8, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Title D-Link DWR-M961 Buffer Overflow via quicksetup.cgi
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:21:19.315Z

Reserved: 2026-08-08T16:43:04.177Z

Link: CVE-2026-71958

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T18:30:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')