D-Link R95 BE9500 DHMAPI OS Command Injection via NTPServer Parameter
First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 9.1
A critical OS command injection vulnerability affects the D-Link R95 BE9500 router (firmware 1.00.16), residing in the DHMAPI component's /bin/ssi system function. Attackers can remotely exploit this by manipulating the NTPServer argument to execute arbitrary OS commands without authentication. A public exploit is available, significantly increasing the likelihood of widespread exploitation.
Technical Analysis
The vulnerability stems from insufficient input sanitization of the NTPServer parameter passed to the system() function within /bin/ssi, part of the DHMAPI component on D-Link R95 BE9500 devices running firmware 1.00.16. This allows an unauthenticated remote attacker to inject arbitrary shell commands, achieving full command execution with the privileges of the underlying service, likely root given typical embedded Linux router architectures. With a CVSS score of 9.1 and a publicly available exploit, this vulnerability is highly attractive to botnet operators and initial access brokers for mass scanning and compromise of exposed devices. Organizations running AI agents or automation frameworks on networks behind compromised D-Link routers face risk of network-level man-in-the-middle attacks, DNS/NTP manipulation, or lateral movement into agent infrastructure, potentially exposing API keys, credentials, or RAG pipeline traffic transiting the compromised network device.
Affected Systems
D-Link R95 BE9500 router, firmware version 1.00.16, specifically the DHMAPI component and /bin/ssi binary handling NTP server configuration
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published at this time; monitor for anomalous NTPServer configuration requests and unexpected outbound connections from D-Link R95 BE9500 devices
Remediation Steps
- 1
Apply Vendor Patch
Check D-Link's security advisories for a firmware update addressing this vulnerability and apply it immediately once available.
- 2
Restrict Remote Access
Disable remote management interfaces and restrict administrative access to trusted internal networks only via firewall rules.
- 3
Network Segmentation
Isolate router administrative functions from critical infrastructure, including any hosts running AI agent frameworks or handling sensitive credentials.
- 4
Monitor for Exploitation
Deploy network intrusion detection signatures targeting anomalous NTPServer parameter injection attempts and unusual command execution patterns on router interfaces.
- 5
Device Replacement Consideration
If no patch is forthcoming from D-Link, consider replacing affected devices with actively supported hardware given the severity and public exploit availability.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.