CVE-2026-1596
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Vendor
Product
CWE
Yayın Tarihi
2026-01-29 16:16:14
Güncelleme
2026-02-10 17:42:17
Source Identifier
cna@vuldb.com
KEV Date Added
-