* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, February 12, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    California Unveils New Mandated Reporter Rules Transforming the Entertainment Industry

    Wildlight Entertainment Faces Setback with Staff Layoffs Soon After Debut Game Launch

    Grammy Award-Winning Singer Ready to Ignite the Stage at Modesto’s Gallo Center – Discover Who and When!

    Watch the U.S. Air Force F-35A Lightning II Light Up the Sky at the Columbus Air Show!

    Black Voices Ignite the Spark at the 2026 Sundance Film Festival

    Rock Legend Defends Bad Bunny’s Epic Halftime Show Performance

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    AITX Surges Nearly 45% to $0.0005: Keep an Eye on RAD Deployments for Recurring Revenue Growth

    NIST Fuels Quantum Technology Breakthroughs with $3.19M Investment in Next-Gen SBIR Projects

    Get Ready for the 2026 NHRA Chassis Certifications at World Wide Technology Raceway – March 14-15!

    John Deere Expands Precision Ag Technology Access – Morning Ag Clips

    Why AI Must Collaborate with Doctors to Create Trustworthy Healthcare Technology

    How Globalization and Technology Are Shaping the Future of Domestic Politics, According to Eswar Prasad

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    California Unveils New Mandated Reporter Rules Transforming the Entertainment Industry

    Wildlight Entertainment Faces Setback with Staff Layoffs Soon After Debut Game Launch

    Grammy Award-Winning Singer Ready to Ignite the Stage at Modesto’s Gallo Center – Discover Who and When!

    Watch the U.S. Air Force F-35A Lightning II Light Up the Sky at the Columbus Air Show!

    Black Voices Ignite the Spark at the 2026 Sundance Film Festival

    Rock Legend Defends Bad Bunny’s Epic Halftime Show Performance

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    AITX Surges Nearly 45% to $0.0005: Keep an Eye on RAD Deployments for Recurring Revenue Growth

    NIST Fuels Quantum Technology Breakthroughs with $3.19M Investment in Next-Gen SBIR Projects

    Get Ready for the 2026 NHRA Chassis Certifications at World Wide Technology Raceway – March 14-15!

    John Deere Expands Precision Ag Technology Access – Morning Ag Clips

    Why AI Must Collaborate with Doctors to Create Trustworthy Healthcare Technology

    How Globalization and Technology Are Shaping the Future of Domestic Politics, According to Eswar Prasad

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hackers exploit critical D-Link DIR-859 router flaw to steal passwords

June 30, 2024
in Technology
Hackers exploit critical D-Link DIR-859 router flaw to steal passwords
Share on FacebookShare on Twitter

Hackers exploit critical D-Link DIR-859 router flaw to steal passwords

Hackers are exploiting a critical vulnerability that affects all D-Link DIR-859 WiFi routers to collect account information from the device, including passwords.

The security issue was disclosed in January and is currently tracked as CVE-2024-0769 (9.8 severity score) – a path traversal flaw that leads to information disclosure.

Although D-Link DIR-859 WiFi router model reached end-of-life (EoL) and no longer receives any updates, the vendor still released a security advisory explaining that the flaw exists in the “fatlady.php” file of the device, affects all firmware versions, and allows attackers to leak session data, achieve privilege escalation, and gain full control via the admin panel.

D-Link is not expected to release a fixing patch for CVE-2024-0769, so owners of the device should switch to a supported device as soon as possible.

Detected exploitation activity

Threat monitoring platform GreyNoise has observed the active exploitation of CVE-2024-0769 in attacks that rely on a slight variation of the public exploit.

The researchers explain that hackers are targeting the ‘DEVICE.ACCOUNT.xml’ file to dump all account names, passwords, user groups, and user descriptions present on the device.

Contents of the retrieved configuration fileContents of the retrieved configuration file
Source: GreyNoise

The attack leverages a malicious POST request to ‘/hedwig.cgi,’ exploiting CVE-2024-0769 to access sensitive configuration files (‘getcfg’) via the ‘fatlady.php’ file, which potentially contains user credentials.

Malicious POST requestMalicious POST request
Source: GreyNoise

GreyNoise has not determined the motivation of the attackers, but the targeting of user passwords shows an intention to perform device takeover, thus giving the attacker full control of the device.

“It is unclear at this time what the intended use of this disclosed information is, it should be noted that these devices will never receive a patch,” the researchers explain.

“Any information disclosed from the device will remain valuable to attackers for the lifetime of the device as long as it remains internet facing” – GreyNoise

GreyNoise notes that the public proof-of-concept exploit, on which current attacks rely, targets the ‘DHCPS6.BRIDGE-1.xml’ file instead of ‘DEVICE.ACCOUNT.xml’, so it could be used to target other configuration files, including:

ACL.xml.php
ROUTE.STATIC.xml.php
INET.WAN-1.xml.php
WIFI.WLAN-1.xml.php

These files could expose configurations for access control lists (ACLs), NAT, firewall settings, device accounts, and diagnostics, so defenders should be aware of them being potential targets for exploitation.

GreyNoise makes available a larger list of files that could be invoked in attacks that exploit CVE-2024-0769. This should server defenders in case other variations occur.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-d-link-dir-859-router-flaw-to-steal-passwords/

Tags: Exploithackerstechnology
Previous Post

Meet Brain Cipher — The new ransomware behind Indonesia’s data center attack

Next Post

Microsoft resumes rollout of Windows 11 KB5039302 update for most users

How Movies Can Transform Society-But Not Through Politics, Says Berlin Film Festival Juror Wim Wenders

February 12, 2026

Russia’s Economy Expected to Slow Further in Early 2026, Minister Warns

February 12, 2026

California Unveils New Mandated Reporter Rules Transforming the Entertainment Industry

February 12, 2026

Humann and Texas Athletics Kick Off Heart Health Month with Thrilling In-Game Celebrations of Cardiovascular Wellness

February 12, 2026

LIVE: Border Czar Tom Homan Addresses Key Issues in Minneapolis Press Conference

February 12, 2026

Exploring the Ecology of the Lower Wisconsin Riverway, Uncovering Microplastic Pollution in the Great Lakes, and A Closer Look at Groundhogs

February 12, 2026

Pacific Science Center Plans to Sell Boeing IMAX Theater and Adjacent Buildings

February 12, 2026

Uncovering the Hidden Dangers of Ignoring Social Science Expertise

February 12, 2026

UK nutritionist shares hack for desk workers: Add 1 simple ingredient to your morning coffee or tea to save your heart | Health – Hindustan Times

February 12, 2026

AITX Surges Nearly 45% to $0.0005: Keep an Eye on RAD Deployments for Recurring Revenue Growth

February 12, 2026

Categories

Archives

February 2026
M T W T F S S
 1
2345678
9101112131415
16171819202122
232425262728  
« Jan    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,070)
  • Economy (1,087)
  • Entertainment (21,964)
  • General (19,866)
  • Health (10,128)
  • Lifestyle (1,102)
  • News (22,149)
  • People (1,096)
  • Politics (1,104)
  • Science (16,303)
  • Sports (21,589)
  • Technology (16,070)
  • World (1,078)

Recent News

How Movies Can Transform Society-But Not Through Politics, Says Berlin Film Festival Juror Wim Wenders

February 12, 2026

Russia’s Economy Expected to Slow Further in Early 2026, Minister Warns

February 12, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version