Python 3 PoC for **[CVE-2026-93958]( — **D-Link R95 BE9500** firmware **BE9500_1.00.16** (build **1.01B06**).
**CVE-2026-93958** — **OS command injection** (CWE-77 / CWE-78) in **`/bin/ssi`** **DHMAPI** (SOAP over HTTPS). The **`SetTimeSettings`** handler stores **`NTPServer`** without sanitization; UCI sync runs **`uci set …="%s"`** via a shell, so **backticks** in `NTPServer` execute as **root**.
**Prerequisites:** Valid **admin** web session (`Login` + **API-AUTH** HMAC). Default user **`Admin`**. Management port commonly **18443** (also try **443**).
**Impact:** Full device compromise (root RCE). **No vendor fix** recorded for **BE9500_1.00.16** (Sep 2026).
**Public research:** [FoundTL/D-Link-R95-BE9500](
**CVSS:** **9.4** (v4.0) / **9.1** (v3.1, `PR:H`, scope changed).
**PoC page:** [
Catalog: [
| **Firmware** | **BE9500_1.00.16** / **1.01B06** |
| **Vector** | `POST /DHMAPI/` → **SetTimeSettings** / **NTPServer** |
| **Exploit** | `` `cmd` `` injection; output via **`/www/pocbit93958.txt`** |
**Features:** Color CLI, **`--mode check`**, **`--mode exploit`**, **mass bulk** (`--list` + `-j`), JSONL + `exploited.txt`.
python poc.py -u 192.168.2.254:18443 --mode check
python poc.py -u 192.168.2.254:18443 -U Admin -P 'YourPass' --mode exploit
python poc.py -u 192.168.2.254:18443 -U Admin -P pass --mode exploit --command "uname -a"
python poc.py --list targets.example.txt --mode exploit -j 8
python poc.py --list targets.txt --mode exploit --password SharedAdminPass -j 12
Target line format: `host[:port] [username] [password]` (tab/space).
CVE-2026-93958 PoC: D-Link **R95 BE9500** DHMAPI **NTPServer** authenticated **root RCE**. DHMAPI login, SetTimeSettings injection, mass exploit. [PoCbit](
Authorized testing on devices you own or may assess only.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
