Perma-Vuln: D-Link DIR-859, CVE-2024-0769
ID: e6cfe983-03c7-5440-b7af-805c9fdf1ac3
STIX ID: report--e6cfe983-03c7-5440-b7af-805c9fdf1ac3
Feed Name: GreyNoise Labs
GreyNoise observed active exploitation of CVE-2024-0769, a path-traversal information-disclosure vulnerability in D-Link DIR-859 routers (all revisions; product is EOL and will not be patched). The report documents the vulnerable hedwig.cgi -> fatlady.php handling, provides a sample POST request used in the wild, demonstrates exfiltration of DEVICE.ACCOUNT (usernames, passwords, groups, descriptions), and lists many other getcfg files that attackers can target, highlighting a long-lived risk for internet-facing devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
