A vulnerability, which was classified as very critical, has been found in D-Link DWR-M961 1.01.07. Affected is an unknown function of the file /boafrm/formPinManageSetup. This manipulation of the argument oldPIn causes command injection.

The identification of this vulnerability is CVE-2026-71952. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.