Overview
D-Link Systems, Inc. has become aware of a reported security vulnerability affecting the D-Link R95, identified as CVE-2026-93958.
The vulnerability reportedly affects the device's DHMAPI component and involves an OS command injectioncondition associated with the system function in /bin/ssi. According to the published CVE information, manipulation of the NTPServer argument may allow unintended operating-system commands to be executed.
The published CVE information indicates that the attack may be performed remotely. Successful exploitation requires elevated privileges, and no user interaction is required. A public proof-of-concept has also been reported.
The published CVE record identifies the affected product as:
Report 1:
-
Product: R95
-
Reported Version: BE9500_1.00.16
-
CVE: CVE-2026-93958
-
Vulnerability Type: OS Command Injection
-
Component: DHMAPI
-
Affected File: /bin/ssi
-
Function: system
-
Affected Argument: NTPServer
-
Status: Under Investigation
D-Link is reviewing the reported vulnerability, affected product scope, and available remediation options.
Vulnerability Details
The reported issue involves improper handling of input supplied to the NTPServer argument within the R95's DHMAPIcomponent.
According to the published vulnerability information, specially crafted input supplied through the affected interface may reach the system function without adequate neutralization of operating-system command elements. This condition may allow an authenticated attacker with sufficient privileges to cause unintended commands to be executed by the device.
Successful exploitation could affect the confidentiality, integrity, and availability of the device.
Technical Information
|
CV
|
CVE-2026-93958
|
|
Product
|
R95
|
|
Reported Version
|
BE9500_1.00.16
|
|
Component
|
DHMAPI
|
|
Affected File
|
/bin/ssi
|
|
Function
|
system
|
|
Affected Argument
|
NTPServer
|
|
Vulnerability
|
OS Command Injection
|
|
CWE
|
CWE-78 / CWE-77
|
|
Attack Vector
|
Network
|
|
Attack Complexity
|
Low
|
|
Privileges Required
|
High
|
|
User Interaction Required
|
No
|
|
Public Proof-of-Concept
|
Reported
|
|
Status
|
Under Investigation
|
The CVE Numbering Authority has assigned the vulnerability a CVSS v3.1 score of 9.1 (Critical) and a CVSS v4.0 score of 9.4 (Critical).
The published CVSS v3.1 vector is:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R
The published CVSS v4.0 vector is:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Affected Product
|
Model
|
Reported Version
|
Hardware Revision
|
Region
|
Security Update
|
|
R95
|
BE9500_1.00.16
|
Rev. Ax
|
All
|
Under Investigation
|
The currently published vulnerability information identifies the D-Link R95 running reported version BE9500_1.00.16 as affected.
D-Link is continuing to verify:
-
the applicable hardware revision or revisions;
-
the geographic or regional product scope;
-
the product lifecycle status;
-
whether other firmware versions are affected; and
-
whether an updated firmware release is available or appropriate.
We will update this announcement as additional verified information becomes available.
Recommended Customer Action
Customers using a D-Link R95 should first verify the exact model, hardware revision, and installed firmware version of their device.
Until D-Link completes its investigation, customers should:
-
Use the AQUILA PRO mobile applicaiton to check and upgrade device
-
Ensure the device's management interfaces are not unnecessarily exposed to the public Internet.
-
Disable or restrict remote management access unless it is specifically required.
-
Limit administrative access to trusted users and trusted systems.
-
Use firewall or network-access controls to restrict access to device-management services.
-
Use strong, unique administrative credentials.
-
Monitor the applicable D-Link regional support site for updated firmware or product-security guidance.
-
Install only firmware specifically intended for the exact product model and hardware revision.
Because the published vulnerability information indicates that elevated privileges are required for exploitation, protecting administrative credentials and restricting access to management interfaces are particularly important while the investigation continues.
If D-Link determines that the affected product or affected firmware is no longer supported, D-Link will provide the appropriate product retirement and replacement guidance.
Hardware Revision and Firmware Notice
D-Link may manufacture products in multiple hardware revisions.
Firmware for one hardware revision may not be compatible with another revision of the same model.
Before installing firmware:
- Confirm the complete product model.
- Confirm the hardware revision shown on the product label.
- Confirm the currently installed firmware version.
- Use the AQUILA PRO mobile applicaiton to check and upgrade device
- Download only firmware designated for that specific model and hardware revision.
- Follow the installation instructions provided by the applicable D-Link support organization.
The hardware revision is normally printed on the product label near the serial number and may also be displayed in the device's web management interface.
Acknowledgment
D-Link acknowledges the security researcher responsible for publicly reporting the vulnerability.
The vulnerability has been assigned:
-
CVE-2026-93958 – D-Link R95 DHMAPI /bin/ssi system NTPServer OS command injection
-
CVE Numbering Authority: VulDB
-
VulDB Reference: VDB-407917
References
-
CVE-2026-93958
-
VulDB VDB-407917