PT-2026-95899 · D Link · R95 Be9500
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link R95 BE9500 version 1.00.16
Description
An OS command injection flaw exists in the DHMAPI component of the device. The issue occurs when the
NTPServer argument is processed by the system() function within the /bin/ssi file. Because the input is passed to a shell command interpreter without sufficient sanitization, a remote attacker can inject and execute arbitrary operating system commands as root. This action can be performed without authentication.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
NTPServer parameter in the affected component to minimize the risk of exploitation.Exploit
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
R95 Be9500