Description
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote OS command execution
Action: Patch Now
AI Analysis

Impact

A vulnerability exists in the system component /bin/ssi of the D-Link R95 router firmware BE9500_1.00.16. By manipulating the NTPServer argument, an attacker can inject arbitrary operating‑system commands. This flaw allows remote execution of malware or deletion of data, presenting a full compromise of the device's confidentiality, integrity, and availability. The weakness is classified as OS command injection and related to improper command sanitization.

Affected Systems

The affected device is the D-Link R95 router running firmware version BE9500_1.00.16. No other products or versions are mentioned as vulnerable, so only this specific build is impacted.

Risk and Exploitability

The CVSS score of 9.4 denotes a critical severity, and the publicly available exploit proves that remote attackers can launch the injection without authentication. The EPSS score is not provided, though the existence of a public exploit suggests a non-trivial attack probability. The vulnerability is not listed in CISA's KEV, but the combination of high severity and exploit availability makes it a high‑risk issue that should be addressed immediately.

Generated by OpenCVE AI on September 20, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware revision from D-Link that addresses the command injection vulnerability.
  • Disable external NTP server configuration or restrict the NTPServer parameter to trusted values.
  • Block inbound access to the DHMAPI service from untrusted networks.

Generated by OpenCVE AI on September 20, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Title D-Link R95 DHMAPI ssi system os command injection
First Time appeared D-link
D-link r95
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:r95:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link r95
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T01:15:12.415Z

Reserved: 2026-09-19T09:12:08.815Z

Link: CVE-2026-93958

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T02:16:53.307

Modified: 2026-09-20T02:16:53.307

Link: CVE-2026-93958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')