---
id: CVE-2026-93958
title: A vulnerability was found in D-Link R95 BE9500_1.00.16
summary: >-
  A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability
  affects the function system of the file /bin/ssi of the component DHMAPI. The
  manipulation of the argument NTPServer results in os command injection. The
  attack c…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-78
vendor: D-Link
product: R95
affected:
  - R95 BE9500_1.00.16
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:18.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93958'
references:
  - url: 'https://github.com/FoundTL/D-Link-R95-BE9500'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-93958'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/944149'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407917'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407917/cti'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.02702
epssPercentile: 0.85312
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/HackSpeak/CVE-2026-93958'
  checkedAt: '2026-09-25T08:21:25.224Z'
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T18:12:04.595932Z'
ingestedAt: '2026-09-20T02:12:35.982Z'
---

## Overview

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
