Sceawere

Vulnerability Detail

CVE-2026-93958UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link R95 OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
D-Link
Product
R95
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-09-20T02:16:53.307Z",
  "pubdate": "2026-09-20T02:16:53.307Z",
  "executiveSummary": "A critical OS command injection vulnerability exists within the DHMAPI component of the D-Link R95 BE9500_1.00.16 router.\nThe vulnerability resides in the /bin/ssi binary, specifically triggered via improper input validation of the NTPServer argument.\nThis flaw allows a remote, unauthenticated attacker to execute arbitrary system commands with elevated privileges on the underlying host operating system.\nSuccessful exploitation compromises the confidentiality, integrity, and availability of the device, effectively granting the attacker full control over the router.\nGiven that public exploit code is currently available, this vulnerability poses a severe security risk to all reachable deployments.\nThe attack surface is exposed via remote network interfaces, necessitating immediate defensive measures to prevent unauthorized access and potential lateral movement within the local network.",
  "technicalDetails": "The vulnerability is localized within the DHMAPI implementation inside the /bin/ssi binary, which serves as a handler for web-based requests in D-Link R95 firmware version 1.00.16.\nThe root cause of this vulnerability is the insecure processing of user-supplied input provided to the NTPServer parameter. The application fails to adequately sanitize or escape this input before passing it to system-level calls, resulting in a classic command injection scenario.\nThe attack flow begins with a specially crafted HTTP request sent to the device’s administrative interface. An attacker can inject arbitrary shell metacharacters—such as semicolons, backticks, or pipes—into the NTPServer parameter. When the /bin/ssi function parses this argument, the underlying system shell interprets these characters as command delimiters.\nBecause the /bin/ssi binary runs with elevated privileges, the injected commands are executed with the same level of access. This allows an attacker to spawn reverse shells, install persistent backdoors, exfiltrate sensitive configuration files, or modify device firewall rules to bypass security policies.\nThe exploitation process does not appear to require prior authentication, making the device susceptible to remote code execution (RCE) from any network segment that can reach the web management interface. By manipulating the NTPServer parameter, an attacker can redirect the device to a malicious time server or execute arbitrary diagnostic commands that trigger the command execution chain.\nPost-exploitation impact includes full system compromise. Since the device acts as a gateway, an attacker who gains control over the router can intercept traffic, perform man-in-the-middle (MITM) attacks on connected clients, or leverage the device as a pivot point for further intrusions into the internal network. The presence of publicly available exploit code significantly lowers the barrier to entry for adversaries, allowing even less sophisticated actors to successfully weaponize this vulnerability against vulnerable hardware."
}
CVE-2026-93958: D-Link R95 OS Command Injection (CRITICAL Severity, CVSS: 9.1) | Sceawere