• News/
  • https://www.bleepingcomputer.com/news/security/backdoor-account-found-in-d-link-dir-620-routers/

Backdoor Account Found in D-Link DIR-620 Routers

BleepingComputer
·
Published May 23, 2018
·
Updated

Security researchers have found a backdoor account in the firmware of D-Link DIR-620 routers that allows hackers to take over any device reachable via the Internet. Discovered by Kaspersky Lab researchers, this backdoor grants an attacker access to the device's web panel, and there's no way in which device owners can disable this secret account. The only way to protect devices from getting hacked is to avoid having the router expose its admin panel on the WAN interface, and hence, reachable from anywhere on the Internet. To prevent abuse, Kaspersky researchers have refrained from disclosing the backdoor's account username and password.

The backdoor account (CVE-2018-6213) is just one of four vulnerabilities Kaspersky researchers found in the firmware of these devices following a recent security audit. The other three flaws include: Both CVE-2018-6210 and CVE-2018-6213 are considered dangerous flaws as they allow attackers easy access to the device. The good news is that D-Link DIR-620 devices are older router models and there aren't that many around to exploit. Most of these devices were deployed by Russian, CIS, and Eastern European ISPs as on-premise equipment provided to broadband customers. The vast majority of these devices are located in Russia, and Kaspersky said it already contacted ISPs to inform them of the issue. Shodan searches for these devices reveal less than 100 DIR-620 routers available online, showing that most ISPs have heeded Kaspersky's warnings and res...

Read full article

Affected Software

1 affected component
D-Link DIR-620=1.0.3, =1.0.37, =1.3.1, =1.3.3, =1.3.7, =1.4.0, =2.0.22
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary issue reported in the article?

The article discusses the discovery of a backdoor account in the firmware of D-Link DIR-620 routers.

2

Who discovered the backdoor account in D-Link routers?

The backdoor account was discovered by researchers from Kaspersky Lab.

3

What are the security risks associated with the backdoor in the D-Link DIR-620 routers?

The backdoor allows hackers to potentially take over any device that is reachable via the Internet.

4

Which versions of the D-Link DIR-620 are reported to be affected?

The affected versions include 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22.

5

What action should users of D-Link DIR-620 routers take in response to this security issue?

Users should check for firmware updates or consider replacing their devices to mitigate the risk associated with the backdoor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203