D Link · R95 Be9500 · CVE-2026-93958
**Name of the Vulnerable Software and Affected Versions**
D-Link R95 BE9500 version 1.00.16
**Description**
An OS command injection flaw exists in the DHMAPI component of the device. The issue occurs when the `NTPServer` argument is processed by the `system()` function within the `/bin/ssi` file. Because the input is passed to a shell command interpreter without sufficient sanitization, a remote attacker can inject and execute arbitrary operating system commands as root. This action can be performed without authentication.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the `NTPServer` parameter in the affected component to minimize the risk of exploitation.