First published: Thu Sep 14 2023(Updated: )
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-859 A1 Firmware | =1.05 | |
Dlink Dir-859 A1 Firmware | =1.06-beta01 | |
Dlink Dir-859 A1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39638 is a command injection vulnerability in D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 firmware.
CVE-2023-39638 has a severity score of 9.8 out of 10, indicating a critical vulnerability.
D-LINK DIR-859 A1 firmware versions 1.05 and 1.06B01 Beta01 are affected by CVE-2023-39638.
To fix CVE-2023-39638, update your D-LINK DIR-859 A1 firmware to a version that is not vulnerable.
You can find more information about CVE-2023-39638 on the D-Link website and GitHub repository, as well as in the D-Link security bulletin.