# D-Link DWR-X1820 routers use weak default passwords derived from IMEI numbers, allowing…

Published: 2026-05-28 · Severity: high · Sectors: telecommunications
Canonical: https://vorant.io/reports/02ddc941-8192-40cf-a482-f83594103ad4/d-link-dwr-x1820-routers-use-weak-default-passwords-derived-from-imei-numbers

> D-Link DWR-X1820 routers use weak default passwords derived from IMEI numbers, allowing attackers who know the IMEI to easily predict credentials.

CERT Polska coordinated disclosure of CVE-2026-4377, a vulnerability affecting D-Link DWR-X1820 routers. The flaw stems from the use of weak default passwords that are algorithmically generated from the device's IMEI number. Critically, the router does not enforce a password change upon initial configuration, leaving devices vulnerable to credential prediction attacks.

An attacker who obtains or observes a device's IMEI number can use knowledge of the password generation algorithm to derive the default administrative password. This could enable unauthorized access to router configuration, potentially allowing network interception, traffic manipulation, or use of the device as a pivot point for further attacks. The vulnerability was addressed in firmware version 1.00B16CP.

The issue was responsibly disclosed by security researcher Bartłomiej Włodarski through CERT Polska's coordinated vulnerability disclosure process. Organizations and individuals using affected D-Link DWR-X1820 routers should update to version 1.00B16CP or later and manually change default passwords if they have not already done so.

## Mentioned in this report

- Vulnerabilities: CVE-2026-4377

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-4377

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/02ddc941-8192-40cf-a482-f83594103ad4/d-link-dwr-x1820-routers-use-weak-default-passwords-derived-from-imei-numbers.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
