CVE-2023-39638: Command Injection
Published Sep 14, 2023
·Updated
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbcsystem function at /htdocs/cgibin.
Affected Software
3 affected components
Dlink Dir-859 A1 Firmware=1.05
Dlink Dir-859 A1 Firmware=1.06-beta01
Dlink Dir-859 A1
Event History
Sep 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39638?
CVE-2023-39638 is a command injection vulnerability in D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 firmware.
2
How severe is CVE-2023-39638?
CVE-2023-39638 has a severity score of 9.8 out of 10, indicating a critical vulnerability.
3
Which software versions are affected by CVE-2023-39638?
D-LINK DIR-859 A1 firmware versions 1.05 and 1.06B01 Beta01 are affected by CVE-2023-39638.
4
How can I fix CVE-2023-39638?
To fix CVE-2023-39638, update your D-LINK DIR-859 A1 firmware to a version that is not vulnerable.
5
Where can I find more information about CVE-2023-39638?
You can find more information about CVE-2023-39638 on the D-Link website and GitHub repository, as well as in the D-Link security bulletin.