A remote, unauthenticated buffer overflow in the app.cgi interface of D-Link DWR-M961 routers can crash the device and may permit code execution, and is rated CVSS 9.8 CRITICAL in the NVD entry.
What Is It
CVE-2026-71957 is a classic buffer overflow (CWE-120) in the app.cgi interface of the D-Link DWR-M961. An attacker who writes an overly long string to the netAcc.addlist[].name field can overrun the buffer. The demonstrated outcome is a crash of the affected service. Buffer overflows of this class can in principle be developed into arbitrary command execution, and the CVSS scoring assigned to this issue assumes that worst case, but no public proof-of-concept demonstrating command execution has been observed, and the reliably reproducible impact remains denial of service.
The flaw was disclosed via VulnCheck ([email protected]). Per the NVD record, it was published on 2026-08-08 and currently carries a Received status, meaning the entry has not yet completed NVD analysis and its scoring and metadata may change.
Why It Matters
The CVSS v3.1 base score recorded in the NVD entry is 9.8 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; the CVSS v4.0 score is 9.3 (CRITICAL). These are provider-supplied scores attached to a record still in Received status, so treat them as the disclosing party's assessment rather than a finalized NVD analysis. Every exploitability factor is set to its worst case: network-reachable attack vector, low attack complexity, no privileges required, and no user interaction. Confidentiality, integrity, and availability impacts are all rated HIGH.
In practice, that means anyone who can reach the router's web interface can attempt this. The confirmed outcome, a crash, is a denial of service against the entire downstream network, since this is the edge device that terminates the LTE uplink and routes all traffic behind it. If the overflow does prove weaponizable for code execution, the consequences escalate accordingly, which is why the issue warrants prompt remediation regardless of the current exploit maturity.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog based on the supplied data; no active exploitation has been confirmed and no KEV remediation deadline applies.
What's Vulnerable
- Vendor: D-Link Corporation
- Product: DWR-M961 (4G AC1200 LTE Router)
- Hardware version: C1
- Software version cited in the disclosure: 1.1.2_C1_202602110044
- Affected range: all versions prior to 1.1.5_C1_202607071108
Patch Status
The vendor advisory data indicates versions below 1.1.5_C1_202607071108 are affected, making that build the boundary for remediation. D-Link has published a security announcement (SAP10512) covering this issue. Operators running hardware version C1 should consult that advisory and move to a build at or above 1.1.5_C1_202607071108. Until updated, the router's management interface should not be exposed to untrusted networks.
Sources
- NVD entry for CVE-2026-71957; https://nvd.nist.gov/vuln/detail/CVE-2026-71957
- D-Link Security Announcement SAP10512; https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10512
- VulnCheck Advisory: D-Link DWR-M961 Buffer Overflow via app.cgi; https://www.vulncheck.com/advisories/d-link-dwr-m961-buffer-overflow-via-app-cgi
- D-Link DWR-M961 Product Page; https://www.dlink.com/middle-east/en/products/dwr-m961-4g-ac1200-lte-router