CVE-2026-93958 — D-Link R95 BE9500 DHMAPI NTPServer Root Command Injection
September 28, 2026 · 53 views
Authenticated OS command injection (CWE-77/78) in D-Link R95 BE9500 firmware BE9500_1.00.16 (1.01B06): DHMAPI SetTimeSettings stores NTPServer unsanitized; UCI sync runs shell with backticks as root. Requires admin Login + API-AUTH HMAC (port 18443/443). CVSS 9.1 Critical. Python PoC: check/exploit, mass bulk -j, colored CLI.
Description
Overview
CVE-2026-93958 — OS command injection in /bin/ssi DHMAPI (SOAP over HTTPS) on the D-Link R95 BE9500 (firmware BE9500_1.00.16, build 1.01B06).
The SetTimeSettings handler stores NTPServer without sanitization. UCI sync runs uci set …="%s" via a shell, so backticks in NTPServer execute as root.
| | |
|---|---|
| Product | D-Link R95 BE9500 |
| Firmware | BE9500_1.00.16 / 1.01B06 |
| Vector | POST /DHMAPI/ → SetTimeSettings / NTPServer |
| Auth | Admin Login + API-AUTH HMAC |
| Impact | Root RCE — full device compromise |
| CVSS | 9.4 (v4.0) / 9.1 (v3.1, PR:H) |
Prerequisites: Valid admin web session. Default user Admin. Management port commonly 18443 (also try 443).
Vendor fix: No fix recorded for BE9500_1.00.16 (as of public research, Sep 2026).
Public research: FoundTL/D-Link-R95-BE9500
PoC page: https://pocbit.org/pocs/cve-2026-93958
Bundled tool (Python 3)
Members: download poc.py from this page (View exploit code).
pip install -r requirements.txt
python poc.py -u 192.168.2.254:18443 --mode check
python poc.py -u 192.168.2.254:18443 -U Admin -P 'YourPass' --mode exploit
python poc.py -u 192.168.2.254:18443 -U Admin -P pass --mode exploit --command "uname -a"
python poc.py --list targets.example.txt --mode exploit -j 8
python poc.py --list targets.txt --mode exploit --password SharedAdminPass -j 12
Target line format: host[:port] [username] [password] (tab/space).
Features: Color CLI, --mode check, --mode exploit, mass bulk (--list + -j), JSONL + exploited.txt.
Impact
Authenticated attackers with admin credentials (or stolen admin session) can achieve root command execution on affected routers — configuration tampering, lateral movement, botnet recruitment.
Remediation
- Restrict management interface to trusted networks; disable WAN admin access.
- Monitor for vendor firmware updates beyond BE9500_1.00.16.
- Rotate admin credentials after any suspected compromise.
Legal and ethical use
Authorized testing on devices you own or may assess only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- IoT / OTCVE-2026-100740high
CVE-2026-100740 — D-Link DIR-895L L2TP Host Name AVP Out-of-Bounds Write
Out-of-bounds write (CWE-787 / CWE-119) in D-Link DIR-895L firmware A1_102b07 L2TP tunnel_set_params() — Host Name AVP length clamped to 127 but NUL written at peer_hostname[len+1] on a 128-byte buffer. Remote attack over UDP 1701 when L2TP is active. PoC fingerprints the router, probes UDP 1701, optional lab-only --oob-send trigger. No vendor fix listed in NVD at publication.
- IoT / OTCVE-2026-13249critical
CVE-2026-13249 — Honeywell PD45 Unauthenticated File Upload (RCE)
Unauthenticated arbitrary file upload on Honeywell PD45 Industrial Printer HTTPS web admin (firmware F10.19.010040 through before F10.22.030745) — CWE-306/434/78, CVSS 9.8 Critical. Attacker-controlled files may execute on the device. Fixed in firmware F10.22.030745.
- IoT / OTCVE-2026-88772critical
CVE-2026-88772 — Citrix NetScaler ADC/Gateway DTLS Memory Overflow (RCE/DoS)
Memory overflow in Citrix NetScaler ADC and NetScaler Gateway DTLS handling (UDP, typically 443) can lead to remote code execution or denial of service. DTLS is on by default for Gateway VPN virtual servers unless -dtls OFF. Fixed at 14.1-73.37+ and 13.1-64.23+; CTX697096 reports active exploitation of CVE-2026-88772 with sibling CVEs. CVSS 4.0 9.5 Critical. PoC fingerprints Gateway, compares build strings, optional benign DTLS probe — no overflow trigger.
- JoomlaCVE-2026-97160critical
CVE-2026-97160 — Joomla UP Plugin PHP Code Injection ({up php=} eval)
PHP code injection (CWE-94, CVSS 4.0 9.4 Critical) in UP (Universal Plugin) for Joomla (plg_content_up, lomart.fr) 5.0.0–5.2.0 and 6.0.0–6.0.29 via {up php=...} shortcodes processed with eval(). Author save/render bypass on older builds can expose execution to all visitors. Fixed in 5.2.1 and 6.1.0.