CVE-2024-0769
published 2024-01-21CVE-2024-0769: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown…
PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-07-16
Exploited in the wild
EPSS
82.71%
99.6th percentile
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-859 | — | — |
| dlink | dir-859_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link DIR-859 Information Disclosure Attempt (CVE-2024-0769)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:11; content:"/hedwig.cgi"; fast_pattern; http.request_body; content:"/htdocs/webinc/getcfg"; content:".xml"; within:50; reference:url,www.labs.greynoise.io/grimoire/2024-06-25-dlink-again/; reference:cve,2024-0769; classtype:attempted-admin; sid:2055723; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2024_09_03, cve CVE_2024_0769, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, updated_at 2024_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
- →Exploit arrives as an HTTP POST request to /hedwig.cgi; inspect the request body for the path traversal string containing '/htdocs/webinc/getcfg' followed by a '.xml' filename within 50 bytes.
- →The attack manipulates the 'service' POST argument with a path traversal payload targeting XML configuration files under /htdocs/webinc/getcfg/; monitor for this argument pattern in POST bodies to /hedwig.cgi. ↗
- →Successful exploitation leaks session data; monitor for unexpected session token exposure or privilege escalation following POST requests to /hedwig.cgi. ↗
- →The Snort/ET rule (sid:2055723) is classified as plaintext-only (tls_state plaintext); deploy at the network perimeter and internally to catch unencrypted exploitation attempts.
- ·The vulnerability is a perma-vuln on an EOL/EOS device with no vendor patch available; the D-Link DIR-859 (firmware 1.06B01) will never receive a fix. Detection and network isolation are the only mitigations. ↗
- ·CISA's KEV remediation due date is 2025-07-16; organizations still running this device must retire and replace it per vendor instructions as no software fix exists. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck5.3MEDIUM
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w828-74x3-f6hx: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1
ghsa_unreviewed·2024-01-21
CVE-2024-0769 [MEDIUM] CWE-22 GHSA-w828-74x3-f6hx: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
VulnCheck
D-Link DIR-859 Router Path Traversal Vulnerability
vulncheck·2024·CVSS 5.3
CVE-2024-0769 [MEDIUM] CWE-22 D-Link DIR-859 Router Path Traversal Vulnerability
D-Link DIR-859 Router Path Traversal Vulnerability
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Affected: D-Link DIR-859 Router
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of th
CISA
D-Link DIR-859 Router Path Traversal Vulnerability
cisa·2025-06-25·CVSS 9.8
CVE-2024-0769 [CRITICAL] CWE-22 D-Link DIR-859 Router Path Traversal Vulnerability
Vulnerability: D-Link DIR-859 Router Path Traversal Vulnerability
Affected: D-Link DIR-859 Router
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discont
Suricata
ET WEB_SPECIFIC_APPS D-Link DIR-859 Information Disclosure Attempt (CVE-2024-0769)
suricata·2024-09-03·CVSS 5.3
CVE-2024-0769 [MEDIUM] ET WEB_SPECIFIC_APPS D-Link DIR-859 Information Disclosure Attempt (CVE-2024-0769)
ET WEB_SPECIFIC_APPS D-Link DIR-859 Information Disclosure Attempt (CVE-2024-0769)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link DIR-859 Information Disclosure Attempt (CVE-2024-0769)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:11; content:"/hedwig.cgi"; fast_pattern; http.request_body; content:"/htdocs/webinc/getcfg"; content:".xml"; within:50; reference:url,www.labs.greynoise.io/grimoire/2024-06-25-dlink-again/; reference:cve,2024-0769; classtype:attempted-admin; sid:2055723; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2024_09_03, cve CVE_2024_0769, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag C
No public exploits indexed.
Greynoiseio
Perma-Vuln: D-Link DIR-859, CVE-2024-0769
blogs_greynoiseio·2024-06-27·CVSS 5.3
[MEDIUM] Perma-Vuln: D-Link DIR-859, CVE-2024-0769
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Storm⚡️Watch
blogs_greynoiseio
Storm⚡️Watch
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bugzilla
CVE-2024-58021 kernel: HID: winwing: Add NULL check in winwing_init_led()
bugzilla·2025-02-27·CVSS 5.5
CVE-2024-58021 [MEDIUM] CVE-2024-58021 kernel: HID: winwing: Add NULL check in winwing_init_led()
CVE-2024-58021 kernel: HID: winwing: Add NULL check in winwing_init_led()
In the Linux kernel, the following vulnerability has been resolved:
HID: winwing: Add NULL check in winwing_init_led()
devm_kasprintf() can return a NULL pointer on failure,but this
returned value in winwing_init_led() is not checked.
Add NULL check in winwing_init_led(), to handle kernel NULL
pointer dereference error.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025022603-CVE-2024-58021-0769@gregkh/T
https://github.com/c2dc/cve-reported/blob/main/CVE-2024-0769/CVE-2024-0769.mdhttps://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10371https://vuldb.com/?ctiid.251666https://vuldb.com/?id.251666https://github.com/c2dc/cve-reported/blob/main/CVE-2024-0769/CVE-2024-0769.mdhttps://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10371https://vuldb.com/?ctiid.251666https://vuldb.com/?id.251666https://nvd.nist.gov/vuln/detail/CVE-2024-0769https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-0769
2024-01-21
Published
2025-06-25
Added to CISA KEV
Exploited in the wild