CVE-2026-93958 is an authenticated OS command injection vulnerability affecting D-Link R95 BE9500 Wi-Fi 7 Smart Router firmware BE9500_1.00.16. The DHMAPI management component insufficiently neutralizes shell-special characters supplied through the NTPServer argument of time-settings requests. Attacker-controlled input reaches a system-command execution routine, permitting command substitution and arbitrary operating-system command execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authenticated remote OS command-injection flaw in the D-Link R95 BE9500 Wi-Fi 7 Smart Router firmware BE9500_1.00.16. Unsanitized NTPServer input in the DHMAPI /bin/ssi component enables command execution as root, resulting in complete device compromise.
A remotely exploitable OS command-injection vulnerability in the DHMAPI component's /bin/ssi system function on D-Link R95 BE9500 firmware version 1.00.16. Manipulating the NTPServer argument permits command injection; exploitation requires high privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.