Impact
A vulnerability exists in the system component /bin/ssi of the D-Link R95 router firmware BE9500_1.00.16. By manipulating the NTPServer argument, an attacker can inject arbitrary operating‑system commands. This flaw allows remote execution of malware or deletion of data, presenting a full compromise of the device's confidentiality, integrity, and availability. The weakness is classified as OS command injection and related to improper command sanitization.
Affected Systems
The affected device is the D-Link R95 router running firmware version BE9500_1.00.16. No other products or versions are mentioned as vulnerable, so only this specific build is impacted.
Risk and Exploitability
The CVSS score of 9.4 denotes a critical severity, and the publicly available exploit proves that remote attackers can launch the injection without authentication. The EPSS score is not provided, though the existence of a public exploit suggests a non-trivial attack probability. The vulnerability is not listed in CISA's KEV, but the combination of high severity and exploit availability makes it a high‑risk issue that should be addressed immediately.
OpenCVE Enrichment