ZeroHour

CVE-2024-57045

PoC large

Authentication Bypass in D-Link DIR-859 Firmware Leaks Admin Credentials

CVSS 3.1
9.8 critical
EPSS
32%p98
Published
()
Modified
AI analysis

CVE-2024-57045 is an improper-authentication flaw (CWE-287) in D-Link DIR-859 routers running firmware A3 1.05 or earlier that lets an unauthenticated attacker bypass access controls. It is triggered by sending a forged POST request to the router's /getcfg.php page, which returns the device's username and password without any prior authentication or user interaction. An attacker who recovers these credentials gains access to the router's management interface and, from there, potentially to the network it controls. Any DIR-859 (A3 hardware revision) running affected firmware is exposed, with risk greatest for devices whose web interface is reachable from the internet or from untrusted LAN clients. No confirmed in-the-wild exploitation is recorded (not in CISA KEV), but a public proof-of-concept exists and EPSS estimates roughly a 32% probability of exploitation within 30 days, so defenders should treat it as likely to be exploited.

What to do: Inventory networks for DIR-859 (A3) routers on firmware A3 1.05 or earlier and check D-Link's support portal for updated firmware, as no fixed version is provided in the disclosure data. Until patched, restrict the web management interface to trusted LAN segments (disable remote/WAN-side management) and limit untrusted LAN clients, since any client that can reach /getcfg.php can retrieve the credentials. Rotate the administrator username and password after patching or mitigating, and consider replacing the device if it is end-of-life and no firmware fix is released.

Affected
D-Link DIR-859 (A3 hardware revision) router firmwareA3 1.05 and earlier
Estimated exposure
largetens of thousands of internet-exposed DIR-859 routers (est.); total installed base likely higher — The DIR-859 was a widely sold mid-2010s D-Link home router, and public internet scans of discontinued D-Link home-router models typically turn up tens of thousands of exposed units, though no official install count is published.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

Vendors
dlink
Products
dir-859 a3 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news