CVE-2024-0769 is a critical path traversal vulnerability affecting the D-Link DIR-859 router, specifically within the /hedwig.cgi component's HTTP POST Request Handler. This flaw allows remote attackers to manipulate the 'service' argument to access sensitive files, leading to a complete compromise of confidentiality, integrity, and availability. Despite the product being end-of-life and unsupported, this vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and significant community discussion. While no public Metasploit or Nuclei modules exist, media reports indicate hackers are leveraging this flaw to steal passwords.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.06CPE matchmatch criteria | cpe:2.3:o:dlink:dir-859_firmware:1.06:beta1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.