← Vulnerability feed

Vulnerability record · CVE-2024-0769 · published 21 January 2024

CVE-2024-0769: D-Link DIR-859 hedwig.cgi path traversal via service argument

Dlink · Dir 859 Firmware

CVE-2024-0769 is a path traversal flaw in the HTTP POST handler of /hedwig.cgi on D-Link DIR-859 firmware 1.06B01, where the 'service' argument can be manipulated with a crafted path to reach files outside the intended directory. The device is end-of-life and unsupported, so no fix is expected, and a public exploit exists.

9.8 CVSS 3.1 Critical CISA KEV since 25 Jun 2025 EPSS 83% · top 0.3% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 5.0
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, public exploit, and CISA KEV listing with a near-top EPSS percentile make this an urgent risk, compounded by the lack of a vendor fix.

What it is

CVE-2024-0769 is a path traversal flaw in the HTTP POST handler of /hedwig.cgi on D-Link DIR-859 firmware 1.06B01, where the 'service' argument can be manipulated with a crafted path to reach files outside the intended directory. The device is end-of-life and unsupported, so no fix is expected, and a public exploit exists.

Impact

An unauthenticated remote attacker can read arbitrary files on the device, including configuration files such as DHCPS6.BRIDGE-1.xml, which may expose credentials or other sensitive settings. The CVSS vector also rates integrity and availability impact as high, though the description only details the traversal read.

Attack surface

Reachable over the network via an HTTP POST request to /hedwig.cgi; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the vector and description.

Exploitation

The exploit has been publicly disclosed and CISA added it to KEV on 2025-06-25, with EPSS 30-day probability of 0.827 (99.65th percentile). No ransomware campaign use is documented.

What to do

  • Retire and replace the D-Link DIR-859; the vendor confirmed the product is end-of-life and unsupported, so no patch will be issued.
  • If retirement is not immediately possible, isolate the device on a segmented network and block external access to its management and HTTP interfaces.
  • Restrict access to /hedwig.cgi and the router's web interface to trusted administrative networks only.
  • Monitor vendor advisory SAP10371 and CISA KEV guidance for any updated mitigation instructions.

Detection

  • Inspect HTTP POST requests to /hedwig.cgi for traversal sequences such as '../' in the 'service' parameter.
  • Alert on requests to /hedwig.cgi that reference files outside expected web paths, especially getcfg XML files.
  • Monitor router logs for unusual file access or configuration reads from the web interface.
  • Watch for outbound connections from the router to unknown hosts that could indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-0769 to the Known Exploited Vulnerabilities catalog on 25 June 2025 as " D-Link DIR-859 Router Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 July 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-0769 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-17621D-Link DIR-859 UPnP gena.cgi unauthenticated command injectionThe UPnP endpoint /gena.cgi on D-Link DIR-859 firmware 1.05 and 1.06B01 Beta01 fails to sanitize input in an HTTP SUBSCRIBE request, allowing OS comm…KEVEPSS 90%analysed9.8CVE-2023-36092Dlink dir-859 firmware incorrect authorization vulnerabilityAuthentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This v…EPSS 1.7%9.8CVE-2019-20215D-Link DIR-859 ssdpcgi OS command injection via M-SEARCH urnD-Link DIR-859 firmware 1.05 and 1.06B01 Beta01 mishandle the HTTP_ST value in ssdpcgi() in /htdocs/cgibin, allowing OS command injection. The urn: s…EPSS 75%analysed9.8CVE-2019-20216Dlink dir-859 firmware os command injection vulnerabilityD-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi…EPSS 3.7%9.8CVE-2019-20217Dlink dir-859 firmware os command injection vulnerabilityD-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi…EPSS 3.6%7.5CVE-2019-20213Dlink dir-859 firmware injection vulnerabilityD-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc…EPSS 2.2%5.5CVE-2022-25106Dlink dir-859 firmware out-of-bounds write vulnerabilityD-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to ca…EPSS 8.6%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2024-0769), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.