SB2026010612 - Missing Authentication for Critical Function in D-Link DWR-711
Published: January 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authentication for Critical Function (CVE-ID: N/A)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the CGI endpoint does not implement authentication or session validation. A remote attacker can upload arbitrary firmware images on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.