Junglewise Threat Intelligence

CVE-2024-0769: D-Link DIR-859 path traversal in hedwig.cgi

CVE-2024-0769 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-06-25

Vendors: D-Link.

Executive brief

A vulnerability exists in legacy D-Link DIR-859 routers, which are used to provide internet connectivity and network management for homes and small offices. An attacker can remotely access sensitive configuration files and session data, potentially leading to full control of the device. Because these routers have reached end-of-life status, no security patches will be released, and the manufacturer recommends replacing the hardware immediately.

Technical details

A path traversal vulnerability (CWE-22) exists in the /hedwig.cgi file of the D-Link DIR-859 router's HTTP POST Request Handler. By manipulating the 'service' argument with traversal sequences (e.g., ../../../../), a remote, unauthenticated attacker can read arbitrary files from the filesystem, such as DHCPS6.BRIDGE-1.xml. This can lead to the exposure of session data and administrative credentials, facilitating privilege escalation and full device compromise. The vulnerability is confirmed to be exploited in the wild, and since the product is End-of-Life (EOL), no official patch is available; users are advised to retire the hardware.

Affected products

  • D-Link DIR-859 Router 1.06B01 and all legacy versions

Timeline

  • 2024-01-21: disclosed: Initial vulnerability report via VulDB
  • 2024-01-29: advisory: NIST NVD analysis published
  • 2025-06-25: kev added: CISA added to Known Exploited Vulnerabilities catalog

Related threats