CVE-2026-4377: Use of Weak Credentials in D-Link DWR-X1820 router
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number.
This issue was fixed in version 1.00B16CP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4377?
The severity of CVE-2026-4377 is medium with a score of 6.
How do I fix CVE-2026-4377?
To fix CVE-2026-4377, update the D-Link DWR-X1820 router to version 1.00B16CP or later.
What vulnerability does CVE-2026-4377 address?
CVE-2026-4377 addresses the use of weak default credentials generated from the device's IMEI number.
Who is affected by CVE-2026-4377?
Users of the D-Link DWR-X1820 router are affected by CVE-2026-4377 due to its weak default password.
What happens if I don't fix CVE-2026-4377?
If CVE-2026-4377 is not fixed, attackers can easily exploit the weak password to gain unauthorized access to the D-Link DWR-X1820 router.