CVE-2023-39638: D-Link DIR-859 a1 Firmware
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
Affected products
- D-Link DIR-859 a1 Firmware: version 1.05 only; version 1.06 only
Published 2023-09-14. Last modified 2026-06-17.