Hackers are exploiting a critical vulnerability affecting all D-Link DIR-859 WiFi routers and allowing the theft of account, including passwords.

The vulnerability is tracked as CVE-2024-0769 (severity rating 9.8) and is a “path traversal” bug that leads to information disclosure.
It is worth noting that the DIR-859 WiFi router model has reached its end of life (EoL), which means that D-Link is no longer releasing updates for it. However, it has released a security advisory and explained that the vulnerability exists in the device’s “fatlady.php” file. It affects all firmware versions and allows attackers to leak session data, achieve privilege escalation, and gain full control of the device via the admin panel.
See also: Critical vulnerability puts D-Link routers at risk
D-Link is not expected to release a fix for the CVE-2024-0769 vulnerability, so users should use a newer router modelthat is supported by the company if they want to stay safe.
Hackers are already exploiting the vulnerability
Threat monitoring platform GreyNoise has observed active exploitation of the CVE-2024-0769 vulnerability, via a small variation of a public exploit.
The researchers explain that the attackers target the “DEVICE.ACCOUNT.xml” file to steal all account names, passwords ,user groups, and user descriptions present on the device. The attack leverages a malicious POST request to ‘/hedwig.cgi’, to access sensitive configuration files (“getcfg”) via the “fatlady.php” file, which may contain user credentials.
By stealing passwords, hackers are likely trying to take control of the vulnerable device.
“Any information revealed by the device will remain valuable to attackers for the lifetime of the device, as long as it remains open to the internet,” GreyNoise explained.
See also: ASUS: Critical vulnerability affects seven routers
GreyNoise says that the public proof-of-concept exploit used by the hackers targets the “DHCPS6.BRIDGE-1.xml” file instead of “DEVICE.ACCOUNT.xml,” so it can be used to target other configuration files, including:
- ACL.xml.php
- ROUTE.STATIC.xml.php
- INET.WAN-1.xml.php
- WIFI.WLAN-1.xml.php
These files could expose configurations for access control lists (ACLs), NAT, firewall settings ,device accounts, and diagnostics, so defenders should be aware that they are potential targets for exploitation.
See also: TP-Link: Critical vulnerability in Archer C5400X gaming router

Devices that are no longer receiving updates (EoL) are a common target for cyberattacks, as they are and remain vulnerable. This puts users at risk, as they may be unaware of potential threats and vulnerabilities that could compromise their devices.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The CVE-2020-24586 vulnerability in D-Link DIR-859 routers highlights the importance of upgrading to vendor-supported devices. As technology continues to evolve, it is important for users to stay informed about potential threats and take the necessary precautions to protect their personal data and privacy. With a few simple steps, users can better protect their devices and minimize the risk of being targeted by hackers.
Source: www.bleepingcomputer.com
