criticalZero-Day

D-Link R95 BE9500 DHMAPI OS Command Injection via NTPServer Parameter

First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 9.1

os-command-injectionrouter-vulnerabilityd-linkrceiotpublic-exploitnetwork-appliance

A critical OS command injection vulnerability affects the D-Link R95 BE9500 router (firmware 1.00.16), residing in the DHMAPI component's /bin/ssi system function. Attackers can remotely exploit this by manipulating the NTPServer argument to execute arbitrary OS commands without authentication. A public exploit is available, significantly increasing the likelihood of widespread exploitation.

Technical Analysis

The vulnerability stems from insufficient input sanitization of the NTPServer parameter passed to the system() function within /bin/ssi, part of the DHMAPI component on D-Link R95 BE9500 devices running firmware 1.00.16. This allows an unauthenticated remote attacker to inject arbitrary shell commands, achieving full command execution with the privileges of the underlying service, likely root given typical embedded Linux router architectures. With a CVSS score of 9.1 and a publicly available exploit, this vulnerability is highly attractive to botnet operators and initial access brokers for mass scanning and compromise of exposed devices. Organizations running AI agents or automation frameworks on networks behind compromised D-Link routers face risk of network-level man-in-the-middle attacks, DNS/NTP manipulation, or lateral movement into agent infrastructure, potentially exposing API keys, credentials, or RAG pipeline traffic transiting the compromised network device.

Affected Systems

D-Link R95 BE9500 router, firmware version 1.00.16, specifically the DHMAPI component and /bin/ssi binary handling NTP server configuration

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published at this time; monitor for anomalous NTPServer configuration requests and unexpected outbound connections from D-Link R95 BE9500 devices

Remediation Steps

  1. 1

    Apply Vendor Patch

    Check D-Link's security advisories for a firmware update addressing this vulnerability and apply it immediately once available.

  2. 2

    Restrict Remote Access

    Disable remote management interfaces and restrict administrative access to trusted internal networks only via firewall rules.

  3. 3

    Network Segmentation

    Isolate router administrative functions from critical infrastructure, including any hosts running AI agent frameworks or handling sensitive credentials.

  4. 4

    Monitor for Exploitation

    Deploy network intrusion detection signatures targeting anomalous NTPServer parameter injection attempts and unusual command execution patterns on router interfaces.

  5. 5

    Device Replacement Consideration

    If no patch is forthcoming from D-Link, consider replacing affected devices with actively supported hardware given the severity and public exploit availability.

CVE / Advisory IDs

CVE-2026-93958

Industries Most Exposed

Consumer/SMB networkingtelecommunicationsremote/home office infrastructureany sector relying on D-Link consumer-grade routers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.