{"id":"CVE-2026-93958","published":"2026-09-20T02:16:53.307","lastModified":"2026-09-21T19:17:18.593","description":"A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-77","CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://github.com/FoundTL/D-Link-R95-BE9500","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-93958","tags":[]},{"url":"https://vuldb.com/submit/944149","tags":[]},{"url":"https://vuldb.com/vuln/407917","tags":[]},{"url":"https://vuldb.com/vuln/407917/cti","tags":[]},{"url":"https://www.dlink.com/","tags":[]}],"exploitRefs":[{"url":"https://github.com/FoundTL/D-Link-R95-BE9500","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows remote command injection through manipulation of the NTPServer argument, enabling attackers to execute arbitrary commands on the device.","exploitability":"Exploitation is relatively straightforward given the public availability of an exploit, and requires only the ability to manipulate the NTPServer argument.","blast_radius":"If exploited, this could lead to full control of the device, potentially leading to data exfiltration, denial of service, or further network compromise.","remediation":"Upgrade to the fixed version 1.00.17 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","os-command-injection","remote-exploit","patch-available"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:06:02.483Z"}}