Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Hackers Target Vulnerability Found Recently in Long-Discontinued D-Link Routers

GreyNoise observes the first attempts to exploit a path traversal vulnerability in discontinued D-Link DIR-859 WiFi routers.

Attackers have started to exploit a critical-severity vulnerability impacting D-Link DIR-859 WiFi routers, which were discontinued four years ago.

The issue, tracked as CVE-2024-0769 (CVSS score of 9.8), is described as a path traversal flaw in the HTTP POST request handler component of the affected routers that can be exploited remotely without authentication to leak sensitive information.

Proof-of-concept (PoC) code targeting the bug was published in January 2024, shortly after the vulnerability was disclosed publicly and D-Link acknowledged it.

Last week, GreyNoise observed the first in-the-wild attempt to exploit the security defect, using a variation of the publicly available exploit.

Unlike the PoC, which targets a file containing usernames and passwords, the in-the-wild exploit targets a different file to disclose all the sensitive information associated with all user accounts on the device.

“GreyNoise observed a slight variation in-the-wild which leverages the vulnerability to render a different PHP file to dump account names, passwords, groups, and descriptions for all users of the device,” the threat intelligence firm notes.

Advertisement. Scroll to continue reading.

While GreyNoise’s systems caught a single exploitation attempt last week, it would not be surprising to see mass exploitation of the vulnerability soon, given that it affects all D-Link DIR-859 revisions and firmware versions.

Owners of D-Link DIR-859 routers are advised to replace them with newer, supported products. In January, the vendor warned that these devices are no longer receiving fixes.

“It is unclear at this time what the intended use of this disclosed information is, it should be noted that these devices will never receive a patch. Any information disclosed from the device will remain valuable to attackers for the lifetime of the device as long as it remains internet facing,” GreyNoise says.

Related: Recent Zyxel NAS Vulnerability Exploited by Botnet

Related: Recent SolarWinds Serv-U Vulnerability Exploited in the Wild

Related: CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities

Related: Fortinet Patches Code Execution Vulnerability in FortiOS

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.