ZeroHour

CVE-2024-0769

KEV PoC

Unauthenticated Path Traversal in D-Link DIR-859 Router (hedwig.cgi)

CISA: D-Link DIR-859 Router Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
83%p100
Published
()
KEV added
AI analysis

D-Link DIR-859 routers running firmware 1.06B01 contain a critical path traversal flaw (CWE-22, CVSS 9.8) in the HTTP POST request handler of /hedwig.cgi. An unauthenticated remote attacker can manipulate the 'service' parameter with a directory-traversal path (e.g., ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml) to access files outside the intended location. Given the critical rating with high confidentiality, integrity, and availability impacts, successful exploitation can expose sensitive router configuration (potentially including credentials) and lead to full device compromise. Only DIR-859 units still in service are affected: D-Link has confirmed the product is end-of-life, so no patched firmware is available. Exploitation is now in the wild — CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-06-25, EPSS puts 30-day exploitation probability at 82.7%, a public proof-of-concept exists, and news reports indicate threat actors are actively exploiting D-Link DIR-series flaws.

What to do: Because the DIR-859 is end-of-life, there is no firmware fix — replace the router with a currently supported model, as the vendor recommends. If replacement is not immediate, minimize exposure by disabling remote/WAN management access to the device and any port-forwarding or UPnP rules that expose the web interface, and monitor for exploitation attempts against /hedwig.cgi. Federal agencies must follow CISA BOD 22-01 and remediate by the assigned KEV due date.

Affected
D-Link DIR-859 Router (DIR-859 firmware)1.06B01 (confirmed affected; product is end-of-life with no fixed release, so all in-service DIR-859 units should be treated as affected)
Estimated exposure
Unknown; plausibly tens of thousands of DIR-859 units remain deployed, with an internet-exposed subset likely in the thousands — No public internet-scan counts exist for this end-of-life consumer model; the estimate reflects the typical lingering install base of a discontinued D-Link consumer router line that sold for several years before retirement.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CISA Known Exploited Vulnerability
Affected
D-Link DIR-859 Router
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-859 firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news