{"cveID":"CVE-2024-0769","vendorProject":"D-Link","product":"DIR-859 Router","vulnerabilityName":" D-Link DIR-859 Router Path Traversal Vulnerability","dateAdded":"2025-06-25","shortDescription":"D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-07-16","knownRansomwareCampaignUse":"Unknown","notes":"https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10371 ; https://nvd.nist.gov/vuln/detail/CVE-2024-0769","cwes":["CWE-22"],"year":2024,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2024-0769","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"dir_traversal","comments":"This path traversal vulnerability in D-Link DIR-859 WiFi routers can lead to information disclosure, such as configuration files. As these devices are end-of-life, the manufacturer has no intention of patching this.","references":["https://securityaffairs.com/165045/hacking/d-link-dir-859-actively-exploited.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-0769","technique":"T1005","technique_name_at_mapping":"Data from Local System","mapping_type":"primary_impact","capability_group":"dir_traversal","comments":"This path traversal vulnerability in D-Link DIR-859 WiFi routers can lead to information disclosure, such as configuration files. As these devices are end-of-life, the manufacturer has no intention of patching this.","references":["https://securityaffairs.com/165045/hacking/d-link-dir-859-actively-exploited.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Local System","name_at_mapping":"Data from Local System","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 05:55 UTC","_attack_version":"19.2"}