<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:dlink:r95_be9500_firmware:1.00.16:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3odlinkr95_be9500_firmware1.00.16/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 20 Sep 2026 04:17:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3odlinkr95_be9500_firmware1.00.16/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in D-Link R95 BE9500</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93958/</link><pubDate>Sun, 20 Sep 2026 04:17:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93958/</guid><description>A critical command injection vulnerability in the D-Link R95 BE9500 firmware (1.00.16) allows remote attackers to execute arbitrary OS commands via the DHMAPI component.</description><content:encoded><![CDATA[<p>CVE-2026-93958 describes a critical command injection vulnerability in the D-Link R95 BE9500 router running firmware version 1.00.16. The vulnerability resides within the DHMAPI component, specifically in the system function of the /bin/ssi binary. An unauthenticated remote attacker can exploit this by manipulating the NTPServer argument during the network time synchronization process. Successful exploitation allows for the execution of arbitrary operating system commands with elevated privileges on the affected device. Public exploit code is currently available, increasing the risk of exploitation by opportunistic actors targeting network infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to full remote code execution on the D-Link R95 BE9500 router. This could allow an attacker to gain persistent access, intercept network traffic, pivot into the internal network, or disable security features on the gateway, potentially affecting all connected clients within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of D-Link R95 BE9500 devices within the infrastructure. Monitor network traffic directed at these devices for patterns indicative of command injection attempts against the NTPServer parameter. Given the public availability of exploits for CVE-2026-93958, organizations should restrict management interface access to trusted administrative networks and apply any available vendor firmware patches immediately.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>cve</category><category>network-security</category></item></channel></rss>