CVE-2024-0769Active Exploitation(dlink / dir-859)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch dlink dir-859 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-859
  • dir-859_firmware

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-01); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dir-859dir-859_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-13: 1Mentions · 2026-05-01: 3Mentions · 2026-06-14: 1PoC Mentioned / Linked · 2026-05-01: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-05-01: 3Patch / Workaround · 2026-06-14: 1Technical Details · 2026-04-13: 1Technical Details · 2026-06-14: 104-1305-0106-14
Signal classification2 categories
Active Exploitation
480.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-131
Active Exploitation1
2026-05-013
Active Exploitation3
2026-06-141
Disclosure1
Full discourse5 posts
  • CVE Brief@DailyCVEBrief
    Disclosure

    LOOK BACK — CVE-2024-0769 lets anyone on the network read admin credentials off a D-Link DIR-859 router. D-Link never patched it: the device was already end-of-life. GreyNoise calls it a "perma-vuln" — the only fix is to retire the hardware. https://t.co/oCwUnOLCwR

    Post summary

    The tweet announces that CVE‑2024‑0769 allows network users to read admin credentials on D‑Link DIR‑859 routers, with no patch available—only hardware retirement serves as the remedy.

    1000075
    18 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2024-0769 to the Known Exploited Vulnerabilities catalog, signaling active exploitation and setting a remediation due date of 2025-07-16 CISA KEV

    Post summary

    CISA’s inclusion of CVE‑2024‑0769 in the Known Exploited Vulnerabilities catalog confirms that the vulnerability is being actively exploited in the wild.

    1000059
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-0769. What happened CISA added CVE-2024-0769 to the Known Exploited Vulnerabilities catalog, signaling active exploitation and setting a remediation due date of 2025-07-16 CISA KEV.

    Post summary

    CISA catalogs CVE-2024-0769 as an actively exploited vulnerability, specifying a remediation deadline of July 16, 2025.

    1000082
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-0769-dir-859-router #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Research indicates that CVE-2024-0769 is actively exploited against DIR‑859 routers, though no patch or detailed technical data is provided.

    0000067
    152 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2024-0769 Exploit in the wild confirmed for CVE-2024-0769 (CVSS null). D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2024-0769 is a path traversal flaw in D‑Link DIR‑859 routers, with confirmed in‑the‑wild exploitation and no patch or PoC details provided.

    00000106
    5.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-859---
OSdlinkdir-859_firmware1.06--

Explore more