Remote Command Injection in D-Link R95 BE9500
A critical command injection vulnerability in the D-Link R95 BE9500 firmware (1.00.16) allows remote attackers to execute arbitrary OS commands via the DHMAPI component.
CVE search metadata
CVE search record: CVE-2026-93958. Severity: critical. CVSS: 9.1. KEV: no. Product: R95 BE9500 (1.00.16). Brief: Remote Command Injection in D-Link R95 BE9500. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93958/
CVE-2026-93958 describes a critical command injection vulnerability in the D-Link R95 BE9500 router running firmware version 1.00.16. The vulnerability resides within the DHMAPI component, specifically in the system function of the /bin/ssi binary. An unauthenticated remote attacker can exploit this by manipulating the NTPServer argument during the network time synchronization process. Successful exploitation allows for the execution of arbitrary operating system commands with elevated privileges on the affected device. Public exploit code is currently available, increasing the risk of exploitation by opportunistic actors targeting network infrastructure.
Impact
Successful exploitation leads to full remote code execution on the D-Link R95 BE9500 router. This could allow an attacker to gain persistent access, intercept network traffic, pivot into the internal network, or disable security features on the gateway, potentially affecting all connected clients within the environment.
Recommendation
Prioritize the identification of D-Link R95 BE9500 devices within the infrastructure. Monitor network traffic directed at these devices for patterns indicative of command injection attempts against the NTPServer parameter. Given the public availability of exploits for CVE-2026-93958, organizations should restrict management interface access to trusted administrative networks and apply any available vendor firmware patches immediately.
Immediate actions
Inventory all D-Link R95 BE9500 devices and verify firmware versions.
Mitigations
Restrict management interface access to the affected devices to trusted management subnets only.
CVE-2026-93958