D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
- https://www.dlink.com/en/security-bulletin/
- https://github.com/ARPSyndicate/cve-scores