CVE-2024-0769
KEV PoCUnauthenticated Path Traversal in D-Link DIR-859 Router (hedwig.cgi)
CISA: D-Link DIR-859 Router Path Traversal Vulnerability
D-Link DIR-859 routers running firmware 1.06B01 contain a critical path traversal flaw (CWE-22, CVSS 9.8) in the HTTP POST request handler of /hedwig.cgi. An unauthenticated remote attacker can manipulate the 'service' parameter with a directory-traversal path (e.g., ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml) to access files outside the intended location. Given the critical rating with high confidentiality, integrity, and availability impacts, successful exploitation can expose sensitive router configuration (potentially including credentials) and lead to full device compromise. Only DIR-859 units still in service are affected: D-Link has confirmed the product is end-of-life, so no patched firmware is available. Exploitation is now in the wild — CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-06-25, EPSS puts 30-day exploitation probability at 82.7%, a public proof-of-concept exists, and news reports indicate threat actors are actively exploiting D-Link DIR-series flaws.
What to do: Because the DIR-859 is end-of-life, there is no firmware fix — replace the router with a currently supported model, as the vendor recommends. If replacement is not immediate, minimize exposure by disabling remote/WAN management access to the device and any port-forwarding or UPnP rules that expose the web interface, and monitor for exploitation attempts against /hedwig.cgi. Federal agencies must follow CISA BOD 22-01 and remediate by the assigned KEV due date.
| D-Link DIR-859 Router (DIR-859 firmware) | 1.06B01 (confirmed affected; product is end-of-life with no fixed release, so all in-service DIR-859 units should be treated as affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
- Affected
- D-Link DIR-859 Router
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dir-859 firmware
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H