CVE-2026-1596 | D-Link DWR-M961 1.1.47 formLtefotaUpgradeQuectel sub_419920 fota_url command injection (EUVD-2026-4953)
A vulnerability was found in D-Link DWR-M961 1.1.47. It has been rated as critical. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection.
This vulnerability is tracked as CVE-2026-1596. The attack is possible to be carried out remotely. Moreover, an exploit is present.