CVE-2026-93958
9.1D-Link · R95
A remote OS command injection vulnerability exists in the D-Link R95 router due to improper input validation of the NTPServer argument within the DHMAPI component.
Executive summary
A critical OS command injection vulnerability in the D-Link R95 router allows an authenticated attacker to execute arbitrary system commands remotely.
Vulnerability
This flaw involves OS command injection within the system function of the /bin/ssi file, specifically triggered by manipulating the NTPServer argument. While the CVSS vector indicates that high privileges are required for exploitation, the impact is severe, allowing an attacker to achieve full system compromise.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with elevated privileges on the affected device. This could lead to a total loss of confidentiality, integrity, and availability of the router, potentially serving as a pivot point for further attacks on the internal network. Given the critical CVSS score of 9.1, this vulnerability poses a significant risk to organizational infrastructure and network security.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict management interface access to trusted IP addresses only and disable unnecessary remote administration features.
Proactive Monitoring: Security teams should monitor system logs for suspicious process execution or attempts to modify NTP configuration settings.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to block unauthorized access to the router management interface, effectively isolating the vulnerable DHMAPI component from untrusted networks.
Exploitation status
Public Exploit Available: Yes, a public proof of concept is available via the GitHub repository referenced in the CVE record.
Analyst recommendation
The severity of this command injection vulnerability necessitates immediate attention to prevent unauthorized system access. Organizations currently using the D-Link R95 with firmware version BE9500_1.00.16 must prioritize isolating these devices from external access until a vendor-supplied firmware update is released and applied.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by Legion_TL (VulDB User), per the CVE Program record.
- VDB-407917 | D-Link R95 DHMAPI ssi system os command injection Vulnerability database entry
- VDB-407917 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-93958 | CVE Analysis and Report Third-party advisory
- Submit #944149 | DLink R95 1.01B06 CWE-78 Third-party advisory
- Exploit / PoC
- dlink.com