{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/r95-be9500-1.00.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:dlink:r95_be9500_firmware:1.00.16:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-93958"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["R95 BE9500 (1.00.16)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cve","network-security"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eCVE-2026-93958 describes a critical command injection vulnerability in the D-Link R95 BE9500 router running firmware version 1.00.16. The vulnerability resides within the DHMAPI component, specifically in the system function of the /bin/ssi binary. An unauthenticated remote attacker can exploit this by manipulating the NTPServer argument during the network time synchronization process. Successful exploitation allows for the execution of arbitrary operating system commands with elevated privileges on the affected device. Public exploit code is currently available, increasing the risk of exploitation by opportunistic actors targeting network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full remote code execution on the D-Link R95 BE9500 router. This could allow an attacker to gain persistent access, intercept network traffic, pivot into the internal network, or disable security features on the gateway, potentially affecting all connected clients within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of D-Link R95 BE9500 devices within the infrastructure. Monitor network traffic directed at these devices for patterns indicative of command injection attempts against the NTPServer parameter. Given the public availability of exploits for CVE-2026-93958, organizations should restrict management interface access to trusted administrative networks and apply any available vendor firmware patches immediately.\u003c/p\u003e\n","date_modified":"2026-09-20T04:17:05Z","date_published":"2026-09-20T04:17:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93958/","summary":"A critical command injection vulnerability in the D-Link R95 BE9500 firmware (1.00.16) allows remote attackers to execute arbitrary OS commands via the DHMAPI component.","title":"Remote Command Injection in D-Link R95 BE9500","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93958/"}],"language":"en","title":"CraftedSignal Threat Feed - R95 BE9500 (1.00.16)","version":"https://jsonfeed.org/version/1.1"}