A vulnerability classified as very critical was found in D-Link DWR-M961 1.01.07. This impacts an unknown function of the file /boafrm/formIMEISetup of the component IMEISetup Interface. The manipulation of the argument IMEI_value results in command injection.

This vulnerability was named CVE-2026-71951. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.