CISA Issues Alert on D-Link Path Traversal Vulnerability Targeted in Attacks

Security researchers have confirmed active exploitation of CVE-2024-0769, a critical path traversal vulnerability (CVSS 9.8) affecting all D-Link DIR-859 WiFi routers.

This flaw enables unauthenticated attackers to access sensitive configuration files, extract credentials, and gain full device control.

The routers reached end-of-life (EoL) in December 2020, meaning no security patches will be released, leaving devices permanently vulnerable.

Vulnerability Mechanics and Exploitation

The flaw resides in the /hedwig.cgi HTTP POST request handler, where manipulation of the service The argument allows directory traversal.

Attackers craft inputs like ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml to bypass security controls (CWE-22).

Observed exploits target DEVICE.ACCOUNT.xml to extract:

  • Usernames and passwords
  • User group permissions
  • Account descriptions
    GreyNoise Labs confirmed in-the-wild attacks using modified public exploit code, with malicious POST requests sent to /hedwig.cgi.
  • The exploit leverages the router’s fatlady.php file to access configuration data, potentially exposing firewall settings, NAT rules, and access controls.

Risks and Threat Landscape

With 87/100 on the SVRS risk scale, compromised routers enable:

  1. Full device takeover: Attackers gain admin panel access for DNS hijacking, traffic interception, or botnet enrollment.
  2. Network compromise: Stolen credentials facilitate lateral movement within connected networks.
  3. Permanent exposure: EoL status guarantees zero patches, making every internet-facing DIR-859 a persistent threat.
    CISA added CVE-2024-0769 to its Known Exploited Vulnerabilities (KEV) catalog on June 25, 2025, noting federal agencies must remediate by July 16, 2025.

Mitigation and Replacement Imperatives

D-Link’s advisory mandates immediate device retirement.

For organizations unable to replace routers immediately:

  • Disable remote management interfaces
  • Implement VPNs for encrypted traffic
  • Rotate admin passwords every 72 hours
  • Monitor logs for anomalous POST requests to /hedwig.cgi
    Federal agencies must comply with Binding Operational Directive (BOD) 22-01 by the July 16 deadline, isolating or decommissioning affected devices.
  • No workaround exists; replacement with supported hardware remains the only secure option.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories