CVE database and vulnerability tracking
D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
CVSS
9.3EPSS
Published
Aug 8, 2026
D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
CVSS
9.3EPSS
Published
Aug 8, 2026
D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
CVSS
9.3EPSS
Published
Aug 8, 2026
MSI Radix AXE6600 v781521 Command Injection via portFw function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
CVSS
9.3EPSS
Published
Aug 8, 2026
MSI Radix AXE6600 v781521 Command Injection via openvpn function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
CVSS
9.3EPSS
Published
Aug 9, 2026
WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVSS
9.8EPSS
Published
Aug 6, 2026