CVE-2026-93958 PUBLISHED

D-Link R95 DHMAPI ssi system os command injection

Assigner: VulDB
Reserved: 19.09.2026 Published: 20.09.2026 Updated: 20.09.2026

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 9.4

Product Status

Vendor D-Link
Product R95
Versions
  • Version BE9500_1.00.16 is affected

Credits

  • Legion_TL (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE