A vulnerability was found in D-Link DWR-M961 up to 1.1.5_C1_202607071107 and classified as very critical. This affects an unknown part of the file /boafrm/formWsc of the component Wsc interface. Executing a manipulation of the argument localPin/targetAPSsid/peerPin/peerRptPin can lead to command injection.
This vulnerability is tracked as CVE-2026-71955. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.