VYPR
Unrated severityNVD Advisory· Published Sep 14, 2023· Updated Sep 26, 2024

CVE-2023-39638

CVE-2023-39638

Description

D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A command injection vulnerability exists in D-Link DIR-859 A1 firmware 1.05 and 1.06B01 Beta01 via the `lxmldbc_system` function in `/htdocs/cgibin`.

Vulnerability

A command injection vulnerability exists in the D-Link DIR-859 A1 router with firmware versions 1.05 and 1.06B01 Beta01. The flaw is located in the lxmldbc_system function within the /htdocs/cgibin binary. An attacker can trigger the injection by sending specially crafted input that is not properly sanitized before being passed to a system command execution [1][2].

Exploitation

An attacker must have network access to the affected device, typically on the local network. No authentication is required to reach the vulnerable code path. The attacker sends a crafted HTTP request to the cgibin interface with malicious input in a parameter that is processed by the lxmldbc_system function, leading to arbitrary command execution [2].

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the device with root privileges. This can lead to full compromise of the router, including disclosure of sensitive configuration data, modification of settings, denial of service, or use as a pivot point for further attacks on the network [2].

Mitigation

As of the publication date (2023-09-14), no fix has been released by D-Link. The DIR-859 A1 is an end-of-life (EOL) product, and D-Link does not intend to issue a security update [1]. Users are advised to replace the device with a supported model or isolate it from untrusted networks as a workaround. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dlink/DIR-859cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 1.05 and 1.06B01 Beta01

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.