CVE-2026-93958: D-Link R95 DHMAPI ssi system os command injection
A vulnerability was found in D-Link R95 BE95001.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerable DHMAPI endpoint can be attacked remotely, but the available CVSS vector indicates that the attacker needs high privileges. No user interaction is required.
Which configuration input is involved?
The injection occurs when the DHMAPI component passes a manipulated NTPServer argument to the system function in /bin/ssi. Systems exposing this functionality to highly privileged users are relevant to triage.
How serious is successful exploitation?
Successful exploitation can result in operating-system command injection with high impact to confidentiality, integrity, and availability. The CVSS vector also indicates scope change.
Is there evidence of exploitation tooling?
A public exploit has been disclosed and could be used. Treat affected D-Link R95 BE9500 devices running version 1.00.16 as requiring prompt review.