Executive brief
The D-Link R95 BE9500 router contains a critical vulnerability in its DHMAPI component that allows remote attackers to execute arbitrary OS commands by manipulating the NTPServer parameter. An attacker exploiting this flaw can gain complete control of the router and its network, potentially compromising all devices and data passing through it. The vulnerability is easily exploitable remotely and exploit code is publicly available.
Technical details
The vulnerability is an OS command injection flaw in the /bin/ssi binary of the DHMAPI component, where the NTPServer argument is not properly sanitized before being passed to system commands. An unauthenticated remote attacker can craft malicious input to inject arbitrary shell commands, leading to code execution with the privileges of the DHMAPI process. The vulnerability is remotely exploitable with no authentication or user interaction required.
Affected products
- D-Link R95 BE9500 1.00.16
Timeline
- 2026-09-20: disclosed: Vulnerability published and exploit made public