D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
- https://github.com/Insight8991/iot/blob/main/dir859%20Command%20Execution%20Vulnerability.md
No PoCs found on GitHub currently.