Home
MEDIUM: 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
1.00B14CP (custom) before 1.00B16CP
affected
Description
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number. This issue was fixed in version 1.00B16CP.
Problem types
CWE-1391 Use of Weak Credentials
Product status
1.00B14CP (custom) before 1.00B16CP
Credits
Bartłomiej Włodarski
References
cert.pl/posts/2026/05/CVE-2026-4377
www.dlink.com/pl/pl/products/dwr-1820-cp