Security researchers have confirmed active exploitation of CVE-2024-0769, a critical path traversal vulnerability (CVSS 9.8) affecting all D-Link DIR-859 WiFi routers.
This flaw enables unauthenticated attackers to access sensitive configuration files, extract credentials, and gain full device control.
The routers reached end-of-life (EoL) in December 2020, meaning no security patches will be released, leaving devices permanently vulnerable.
Vulnerability Mechanics and Exploitation
The flaw resides in the /hedwig.cgi HTTP POST request handler, where manipulation of the service The argument allows directory traversal.
Attackers craft inputs like ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml to bypass security controls (CWE-22).
Observed exploits target DEVICE.ACCOUNT.xml to extract:
- Usernames and passwords
- User group permissions
- Account descriptions
GreyNoise Labs confirmed in-the-wild attacks using modified public exploit code, with malicious POST requests sent to/hedwig.cgi. - The exploit leverages the router’s
fatlady.phpfile to access configuration data, potentially exposing firewall settings, NAT rules, and access controls.
Risks and Threat Landscape
With 87/100 on the SVRS risk scale, compromised routers enable:
- Full device takeover: Attackers gain admin panel access for DNS hijacking, traffic interception, or botnet enrollment.
- Network compromise: Stolen credentials facilitate lateral movement within connected networks.
- Permanent exposure: EoL status guarantees zero patches, making every internet-facing DIR-859 a persistent threat.
CISA added CVE-2024-0769 to its Known Exploited Vulnerabilities (KEV) catalog on June 25, 2025, noting federal agencies must remediate by July 16, 2025.
Mitigation and Replacement Imperatives
D-Link’s advisory mandates immediate device retirement.
For organizations unable to replace routers immediately:
- Disable remote management interfaces
- Implement VPNs for encrypted traffic
- Rotate admin passwords every 72 hours
- Monitor logs for anomalous POST requests to
/hedwig.cgi
Federal agencies must comply with Binding Operational Directive (BOD) 22-01 by the July 16 deadline, isolating or decommissioning affected devices. - No workaround exists; replacement with supported hardware remains the only secure option.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates