VORANT. Threat Intelligence Sign in Get the full feed

D-Link DWR-X1820 IMEI-based Password Flaw

medium vulnerability telecommunications

D-Link DWR-X1820 routers generate weak default passwords from device IMEI numbers, letting attackers who know the IMEI easily crack the default credentials.

CERT Polska coordinated the disclosure of CVE-2026-4377, a vulnerability affecting the D-Link DWR-X1820 router in which the default administrative password is derived from the device's IMEI number using a predictable algorithm. Since users are not required to change this default password, an attacker who obtains or guesses the device's IMEI can reconstruct the default credentials and gain unauthorized access to the router's management interface.

The issue was responsibly reported by security researcher Bartłomiej Włodarski and has since been resolved by D-Link in firmware version 1.00B16CP. There is no indication of active exploitation in the wild; this is a standard coordinated vulnerability disclosure. Administrators of affected devices should update to the patched firmware and set a strong, unique administrative password rather than relying on factory defaults.

Mentioned in this report

Vulnerabilities CVE-2026-4377

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-4377

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free