A vulnerability was found in D-Link DWR-M961 up to 1.1.5_C1_202607071107. It has been classified as very critical. This vulnerability affects unknown code of the file app.cgi of the component CGI Interface. The manipulation of the argument netDig.ping.dst leads to command injection.
This vulnerability is listed as CVE-2026-71956. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.