### [CVE-2022-46476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46476) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function. ### POC #### Reference - https://github.com/Insight8991/iot/blob/main/dir859%20Command%20Execution%20Vulnerability.md #### Github No PoCs found on GitHub currently.