D-Link DWR-X1820 weak default passwords from IMEI
D-Link DWR-X1820 routers generate weak default passwords from IMEI numbers, allowing attackers who obtain the IMEI to gain access; patched in firmware 1.00B16CP.
CERT Polska coordinated disclosure of CVE-2026-4377, a vulnerability in D-Link DWR-X1820 routers that use predictable default passwords derived from the device's IMEI number. The router does not enforce password changes upon initial setup, allowing attackers who obtain or guess the IMEI to calculate the default credentials and gain unauthorized access to affected devices.
The vulnerability represents a fundamental weakness in authentication security, as IMEI numbers can often be obtained through various means including physical access to packaging, network scanning, or social engineering. D-Link has released firmware version 1.00B16CP to address the issue. Organizations and individuals using DWR-X1820 routers should update to the patched firmware immediately and change default credentials.
The vulnerability was responsibly disclosed by researcher Bartłomiej Włodarski through CERT Polska's coordinated vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-4377
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free