Vulnerability record · CVE-2024-0769 · published 21 January 2024
CVE-2024-0769: D-Link DIR-859 hedwig.cgi path traversal via service argument
Dlink · Dir 859 Firmware
CVE-2024-0769 is a path traversal flaw in the HTTP POST handler of /hedwig.cgi on D-Link DIR-859 firmware 1.06B01, where the 'service' argument can be manipulated with a crafted path to reach files outside the intended directory. The device is end-of-life and unsupported, so no fix is expected, and a public exploit exists.
Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, public exploit, and CISA KEV listing with a near-top EPSS percentile make this an urgent risk, compounded by the lack of a vendor fix.
What it is
CVE-2024-0769 is a path traversal flaw in the HTTP POST handler of /hedwig.cgi on D-Link DIR-859 firmware 1.06B01, where the 'service' argument can be manipulated with a crafted path to reach files outside the intended directory. The device is end-of-life and unsupported, so no fix is expected, and a public exploit exists.
Impact
An unauthenticated remote attacker can read arbitrary files on the device, including configuration files such as DHCPS6.BRIDGE-1.xml, which may expose credentials or other sensitive settings. The CVSS vector also rates integrity and availability impact as high, though the description only details the traversal read.
Attack surface
Reachable over the network via an HTTP POST request to /hedwig.cgi; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the vector and description.
Exploitation
The exploit has been publicly disclosed and CISA added it to KEV on 2025-06-25, with EPSS 30-day probability of 0.827 (99.65th percentile). No ransomware campaign use is documented.
What to do
- Retire and replace the D-Link DIR-859; the vendor confirmed the product is end-of-life and unsupported, so no patch will be issued.
- If retirement is not immediately possible, isolate the device on a segmented network and block external access to its management and HTTP interfaces.
- Restrict access to /hedwig.cgi and the router's web interface to trusted administrative networks only.
- Monitor vendor advisory SAP10371 and CISA KEV guidance for any updated mitigation instructions.
Detection
- Inspect HTTP POST requests to /hedwig.cgi for traversal sequences such as '../' in the 'service' parameter.
- Alert on requests to /hedwig.cgi that reference files outside expected web paths, especially getcfg XML files.
- Monitor router logs for unusual file access or configuration reads from the web interface.
- Watch for outbound connections from the router to unknown hosts that could indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-0769 to the Known Exploited Vulnerabilities catalog on 25 June 2025 as " D-Link DIR-859 Router Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 July 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/c2dc/cve-reported/blob/main/CVE-2024-0769/CVE-2024-0769.md | ExploitThird Party Advisory |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10371 | Vendor Advisory |
| https://vuldb.com/?ctiid.251666 | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.251666 | Third Party AdvisoryVDB Entry |
| https://github.com/c2dc/cve-reported/blob/main/CVE-2024-0769/CVE-2024-0769.md | ExploitThird Party Advisory |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10371 | Vendor Advisory |
| https://vuldb.com/?ctiid.251666 | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.251666 | Third Party AdvisoryVDB Entry |
| https://nvd.nist.gov/vuln/detail/CVE-2024-0769 | US Government Resource |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-0769 | US Government Resource |
Track CVE-2024-0769 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-0769), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.