# D-Link DWR-X1820 weak default passwords from IMEI

Published: 2026-05-28 · Severity: medium
Canonical: https://vorant.io/reports/5677b8b5-cc37-5f97-b89b-37eeae3c74fd/d-link-dwr-x1820-weak-default-passwords-from-imei

> D-Link DWR-X1820 routers generate weak default passwords from IMEI numbers, allowing attackers who obtain the IMEI to gain access; patched in firmware 1.00B16CP.

CERT Polska coordinated disclosure of CVE-2026-4377, a vulnerability in D-Link DWR-X1820 routers that use predictable default passwords derived from the device's IMEI number. The router does not enforce password changes upon initial setup, allowing attackers who obtain or guess the IMEI to calculate the default credentials and gain unauthorized access to affected devices.

The vulnerability represents a fundamental weakness in authentication security, as IMEI numbers can often be obtained through various means including physical access to packaging, network scanning, or social engineering. D-Link has released firmware version 1.00B16CP to address the issue. Organizations and individuals using DWR-X1820 routers should update to the patched firmware immediately and change default credentials.

The vulnerability was responsibly disclosed by researcher Bartłomiej Włodarski through CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2026-4377

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-4377

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5677b8b5-cc37-5f97-b89b-37eeae3c74fd/d-link-dwr-x1820-weak-default-passwords-from-imei.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
