Skip to content
COOEY

FAIL › dossier

DIR-859 Router

PRODUCT

· dossier confidence 50%

The D-Link DIR-859 router demonstrates a critical security posture characterized by prolonged exposure of high-severity remote code execution vulnerabilities. These unpatched flaws, including path traversal and UPnP exploits, have been actively exploited in the wild, indicating a systemic failure in the vendor's vulnerability management and patch deployment processes for consumer networking hardware.

PROFILE
Categorynetworking hardwareWhat they doD-Link DIR-859 is a consumer-grade router manufactured by D-Link.
SECURITY POSTURE

The DIR-859 router has a poor security track record, with multiple high-severity remote code execution vulnerabilities remaining unpatched for extended periods and actively exploited in the wild.

Notable failures
  • CVE-2024-0769 unpatched path traversal RCE
  • CVE-2019-17621 unauthenticated UPnP RCE
Patterns: repeated unpatched edge-device RCEs; delayed patch deployment for consumer hardware
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-06-25 CVE-2024-0769 high D-Link DIR-859 Router exposed due to unpatched path traversal vulnerability, enabling potential unauthorized control.
2023-06-29 CVE-2019-17621 high A D-Link router allowed unauthenticated attackers to execute commands as root via a UPnP vulnerability, now actively exploited in the wild.
Open questions: D-Link's current vulnerability disclosure policy · Patch frequency for DIR-859 firmware updates
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-16 04:27:41.268805+00:00