Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.5
CVE-2026-93958: D-Link R95 allows remote command execution via NTP setting
CVE-2026-93958 · published 20 days ago
Summary
The D-Link R95 router can be tricked into running unauthorized system commands when an attacker changes the NTP server setting. This can be done from anywhere on the internet, giving the attacker control over the device. Update the router firmware to the latest version or replace the device if a fix is not available.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | r95 | BE9500_1.00.16 |
Original advisory text
D-Link R95 DHMAPI ssi system os command injection
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.5
High
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published20 Sep 2026
Updated10 Oct 2026
First seen20 Sep 2026
Track software like this
Free during beta