LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-0769: D-Link DIR-859 Router Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 25, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 16, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-0769 to its Known Exploited Vulnerabilities catalog on Jun 25, 2025, with a federal patch deadline of Jul 16, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input…

CVE-2024-0769 is a path traversal vulnerability in the D-Link DIR-859 router that can leak session data through a crafted request to a specific CGI handler. Because the device is a network gateway, successful abuse may allow an attacker to escalate privileges and gain unauthorized control of the router, putting the entire attached network at risk. Public detail is limited to the CISA description of this legacy product; confirm all technical specifics against the vendor advisory.

The affected hardware revisions have reached end-of-life (EOL) or end-of-service (EOS). CISA therefore advises retiring and replacing the devices rather than relying on ongoing patches.

How it works

The flaw belongs to CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). On the DIR-859 the HTTP POST Request Handler component processes requests to the file /hedwig.cgi. An attacker who can reach that endpoint can manipulate the service argument with a path-traversal sequence such as the one documented by CISA (../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml). The router then returns configuration or session data that should have remained inaccessible. With that data an attacker may obtain credentials or session tokens that enable privilege escalation and full device control. Exact request formats, authentication requirements, and exploit mechanics must be confirmed against the vendor advisory; no additional exploit details are provided in the public summary.

Am I affected? How to find it in your systems

D-Link DIR-859 routers are typically deployed as consumer or small-office edge gateways. Inventory every network device that presents a web management interface or DHCP/NAT services and identify any unit whose model string is DIR-859. Because all associated hardware revisions are EOL/EOS, any still-running DIR-859 should be treated as affected until proven otherwise.

Telemetry that shows unexpected configuration downloads or sudden administrative session creation should be investigated promptly.

How to remediate

Because the product line has reached EOL/EOS, the primary remediation is to discontinue use of the DIR-859 and replace it with a currently supported router per D-Link’s instructions. Apply any mitigations the vendor still publishes, and follow CISA’s BOD 22-01 guidance where cloud-managed services are involved. If a vendor update is named in the advisory, install it immediately on any remaining units while replacement hardware is procured. After replacement, factory-reset the old device, wipe any stored credentials, and dispose of it securely.

If you can't patch immediately

Until the device can be retired, reduce exposure with compensating controls appropriate to a path-traversal flaw on an edge router.

These measures only buy time; permanent risk reduction requires replacement of the EOL hardware.

If your data may have been exposed

Actively exploited path-traversal flaws on network devices can lead to full compromise and subsequent data exposure. If session data or administrative credentials may have left the device, treat the incident as a potential breach: isolate the router, collect forensic logs, rotate all credentials that traversed the device, and examine downstream systems for lateral movement. Readers can also run a free exposure scan of their email addresses to check whether those addresses appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DIR-859 Router
WeaknessCWE-22
Added to CISA KEVJun 25, 2025
Federal patch deadlineJul 16, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities