CVE-2026-1624 | D-Link DWR-M961 1.1.47 formLtefotaUpgradeFibocom fota_url command injection (EUVD-2026-4939)
A vulnerability was found in D-Link DWR-M961 1.1.47 and classified as critical. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection.
This vulnerability is uniquely identified as CVE-2026-1624. The attack can be launched remotely. Moreover, an exploit is present.