A vulnerability has been found in D-Link DWR-M961 up to 1.1.5_C1_202607071107 and classified as very critical. Affected by this issue is some unknown functionality of the file /boafrm/formL2tpv3ConfigSetup of the component formL2tpv3ConfigSetup. Performing a manipulation of the argument tunnelid/sessionid results in command injection.

This vulnerability is identified as CVE-2026-71954. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.