Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.5

CVE-2026-93958: D-Link R95 allows remote command execution via NTP setting

CVE-2026-93958 · published 20 days ago
Summary

The D-Link R95 router can be tricked into running unauthorized system commands when an attacker changes the NTP server setting. This can be done from anywhere on the internet, giving the attacker control over the device. Update the router firmware to the latest version or replace the device if a fix is not available.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link r95 BE9500_1.00.16
Original advisory text
D-Link R95 DHMAPI ssi system os command injection
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.5 High
Exploitation
3% chance of attack within 30 days
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published20 Sep 2026
Updated10 Oct 2026
First seen20 Sep 2026
Sources
CVE-2026-93958 · MITRE
Track software like this
Free during beta