logo

Hackers exploit critical D-Link DIR-859 router flaw to steal passwords

ID: dc984589-0525-5e78-bb68-d126c242bbd4

STIX ID: report--dc984589-0525-5e78-bb68-d126c242bbd4

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise and other researchers have observed active exploitation of CVE-2024-0769, a critical path traversal flaw in D-Link DIR-859 routers (EoL) that allows attackers to read configuration files (including DEVICE.ACCOUNT.xml) and steal administrative credentials; vendors will not issue patches so affected devices should be replaced or removed from internet-facing access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.