PT-2023-8398 · D Link · D-Link Dir-859

Exord26

+2

·

Publicado

2023-12-15

·

Atualizado

2026-06-14

·

CVE-2024-0769

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-859 version 1.06B01
Description A critical vulnerability has been found in the D-Link DIR-859 router, affecting some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the service argument with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. This issue allows an attacker to gain information within the device and potentially gain full control over it. The attack may be launched remotely. The estimated number of potentially affected devices worldwide is not specified. However, it is mentioned that threat actors are actively exploiting this vulnerability.
Recommendations As a temporary workaround, consider disabling the /hedwig.cgi file until a replacement device is installed. Replace the D-Link DIR-859 router with a supported device as soon as possible, since the vendor has confirmed that the product is end-of-life and no patch will be provided.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00635
CVE-2024-0769

Produtos afetados

D-Link Dir-859