Vulnerabilities > Dlink > DIR 859 A1 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-09-14 CVE-2023-39638 Command Injection vulnerability in Dlink Dir-859 A1 Firmware 1.05/1.06
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
network
low complexity
dlink CWE-77
critical
9.8
2023-01-19 CVE-2022-46476 OS Command Injection vulnerability in Dlink Dir-859 A1 Firmware 1.05
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
network
low complexity
dlink CWE-78
critical
9.8