A vulnerability, which was classified as very critical, was found in D-Link DWR-M961 up to 1.1.5_C1_202607071107. Affected by this vulnerability is an unknown functionality of the file /boafrm/formNtp of the component Ntp interface. Such manipulation of the argument ntpServerIp1 leads to command injection.

This vulnerability is referenced as CVE-2026-71953. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.