Tue, Aug 04 · 07:16 AM CDTCVE-2026-64564
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Addr
CVECVE-2026-64564
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 04 · 07:16 AM CDT
ModifiedSun, Aug 09 · 04:17 AM CDT
Wed, Aug 05 · 08:16 AM CDTCVE-2026-64566
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_skb_add_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via __skb_frag_ref() but does not propagate SKBFL_SHARE
CVECVE-2026-64566
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 05 · 08:16 AM CDT
ModifiedSat, Aug 08 · 03:16 PM CDT
Thu, Aug 06 · 08:16 AM CDTCVE-2026-64597
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response
CVECVE-2026-64597
SeverityCRITICAL
TypeUPDATED
PublishedThu, Aug 06 · 08:16 AM CDT
ModifiedSat, Aug 08 · 03:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71944
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root pri
CVECVE-2026-71944
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 05:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71945
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root pri
CVECVE-2026-71945
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71946
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
CVECVE-2026-71946
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71947
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with
CVECVE-2026-71947
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71948
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges
CVECVE-2026-71948
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71949
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution wit
CVECVE-2026-71949
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71950
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.
CVECVE-2026-71950
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71951
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.
CVECVE-2026-71951
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71952
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
CVECVE-2026-71952
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71953
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
CVECVE-2026-71953
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71954
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution wi
CVECVE-2026-71954
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 05:16 PM CDTCVE-2026-71955
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command executio
CVECVE-2026-71955
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 05:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 06:16 PM CDTCVE-2026-71956
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.
CVECVE-2026-71956
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 06:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 06:16 PM CDTCVE-2026-71957
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the d
CVECVE-2026-71957
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 06:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 06:16 PM CDTCVE-2026-71958
9.8/10 · Must read/watchNVDvuln
Summary
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or
CVECVE-2026-71958
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 06:16 PM CDT
ModifiedSat, Aug 08 · 06:16 PM CDT
Sat, Aug 08 · 11:16 PM CDTCVE-2026-71983
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbit
CVECVE-2026-71983
SeverityCRITICAL
TypeNEW
PublishedSat, Aug 08 · 11:16 PM CDT
ModifiedSat, Aug 08 · 11:16 PM CDT
Sun, Aug 09 · 12:16 AM CDTCVE-2026-71984
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying
CVECVE-2026-71984
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 12:16 AM CDT
ModifiedSun, Aug 09 · 12:16 AM CDT
Sun, Aug 09 · 12:16 AM CDTCVE-2026-71985
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obta
CVECVE-2026-71985
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 12:16 AM CDT
ModifiedSun, Aug 09 · 12:16 AM CDT
Sun, Aug 09 · 12:16 AM CDTCVE-2026-71986
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges o
CVECVE-2026-71986
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 12:16 AM CDT
ModifiedSun, Aug 09 · 12:16 AM CDT
Sun, Aug 09 · 12:16 AM CDTCVE-2026-71987
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges o
CVECVE-2026-71987
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 12:16 AM CDT
ModifiedSun, Aug 09 · 12:16 AM CDT
Sun, Aug 09 · 12:16 AM CDTCVE-2026-71988
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privilege
CVECVE-2026-71988
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 12:16 AM CDT
ModifiedSun, Aug 09 · 12:16 AM CDT
Sun, Aug 09 · 12:16 AM CDTCVE-2026-71989
9.8/10 · Must read/watchNVDvuln
Summary
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privi
CVECVE-2026-71989
SeverityCRITICAL
TypeNEW
PublishedSun, Aug 09 · 12:16 AM CDT
ModifiedSun, Aug 09 · 12:16 AM CDT