PT-2026-95899 · D Link · R95 Be9500

·

CVE-2026-93958

·

Published

2026-08-23

·

Updated

2026-09-25

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link R95 BE9500 version 1.00.16
Description An OS command injection flaw exists in the DHMAPI component of the device. The issue occurs when the NTPServer argument is processed by the system() function within the /bin/ssi file. Because the input is passed to a shell command interpreter without sufficient sanitization, a remote attacker can inject and execute arbitrary operating system commands as root. This action can be performed without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the NTPServer parameter in the affected component to minimize the risk of exploitation.

Exploit

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15577
CVE-2026-93958

Affected Products

R95 Be9500