CVE-2024-0769: D-Link DIR-859 Router Path Traversal Vulnerability

Published Jan 21, 2024
·
Updated

UNSUPPORTED WHEN ASSIGNED A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Other sources

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CISA

Affected Software

3 affected components
All of the following
Dlink Dir-859 Firmware=1.06-beta1
Dlink Dir-859
D-Link DIR-859 Router

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove D-Link DIR-859 from your environment.

    Retire and replace the device; discontinue use of the product as all hardware revisions are end-of-life/end-of-service and the vendor confirmed the product is end-of-life.

  2. Compensating control

    Follow applicable BOD 22-01 guidance for cloud services.

Event History

Jan 21, 2024
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 29, 2024
News Published
via BleepingComputer·03:18 PM
News Published
via BleepingComputer·03:19 PM
Jun 25, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-0769?

CVE-2024-0769 has been rated as a critical vulnerability.

2

What component is affected by CVE-2024-0769?

CVE-2024-0769 affects the HTTP POST Request Handler in D-Link DIR-859 firmware version 1.06-beta1.

3

How do I fix CVE-2024-0769?

To mitigate CVE-2024-0769, users should consider upgrading to a newer, secure version of the firmware if available.

4

What products are affected by CVE-2024-0769?

CVE-2024-0769 specifically affects the D-Link DIR-859 router firmware version 1.06-beta1.

5

What functionality is exploited in CVE-2024-0769?

CVE-2024-0769 involves the manipulation of the 'service' argument in the /hedwig.cgi file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203