CVE-2026-93958

critical

Description

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

References

https://www.dlink.com/

https://vuldb.com/vuln/407917/cti

https://vuldb.com/vuln/407917

https://vuldb.com/submit/944149

https://vuldb.com/cve/CVE-2026-93958

https://github.com/FoundTL/D-Link-R95-BE9500

Details

Source: Mitre, NVD

Published: 2026-09-20

Updated: 2026-09-20

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.4

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Severity: Critical

EPSS

EPSS: 0.02175