POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
IoT / OTcritical

CVE-2026-93958 — D-Link R95 BE9500 DHMAPI NTPServer Root Command Injection

September 28, 2026 · 53 views

Authenticated OS command injection (CWE-77/78) in D-Link R95 BE9500 firmware BE9500_1.00.16 (1.01B06): DHMAPI SetTimeSettings stores NTPServer unsanitized; UCI sync runs shell with backticks as root. Requires admin Login + API-AUTH HMAC (port 18443/443). CVSS 9.1 Critical. Python PoC: check/exploit, mass bulk -j, colored CLI.

#iot#router#d-link#rce#command-injection#authenticated#dhmapi

CVE:

CVE-2026-93958

Date:

2026-09-28

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-93958 — OS command injection in /bin/ssi DHMAPI (SOAP over HTTPS) on the D-Link R95 BE9500 (firmware BE9500_1.00.16, build 1.01B06).

The SetTimeSettings handler stores NTPServer without sanitization. UCI sync runs uci set …="%s" via a shell, so backticks in NTPServer execute as root.

| | | |---|---| | Product | D-Link R95 BE9500 | | Firmware | BE9500_1.00.16 / 1.01B06 | | Vector | POST /DHMAPI/ → SetTimeSettings / NTPServer | | Auth | Admin Login + API-AUTH HMAC | | Impact | Root RCE — full device compromise | | CVSS | 9.4 (v4.0) / 9.1 (v3.1, PR:H) |

Prerequisites: Valid admin web session. Default user Admin. Management port commonly 18443 (also try 443).

Vendor fix: No fix recorded for BE9500_1.00.16 (as of public research, Sep 2026).

Public research: FoundTL/D-Link-R95-BE9500

PoC page: https://pocbit.org/pocs/cve-2026-93958

Bundled tool (Python 3)

Members: download poc.py from this page (View exploit code).

pip install -r requirements.txt

python poc.py -u 192.168.2.254:18443 --mode check
python poc.py -u 192.168.2.254:18443 -U Admin -P 'YourPass' --mode exploit
python poc.py -u 192.168.2.254:18443 -U Admin -P pass --mode exploit --command "uname -a"
python poc.py --list targets.example.txt --mode exploit -j 8
python poc.py --list targets.txt --mode exploit --password SharedAdminPass -j 12

Target line format: host[:port] [username] [password] (tab/space).

Features: Color CLI, --mode check, --mode exploit, mass bulk (--list + -j), JSONL + exploited.txt.

Impact

Authenticated attackers with admin credentials (or stolen admin session) can achieve root command execution on affected routers — configuration tampering, lateral movement, botnet recruitment.

Remediation

  1. Restrict management interface to trusted networks; disable WAN admin access.
  2. Monitor for vendor firmware updates beyond BE9500_1.00.16.
  3. Rotate admin credentials after any suspected compromise.

Legal and ethical use

Authorized testing on devices you own or may assess only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →