PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4377 D-Link Corporation CVE debrief

CVE-2026-4377 documents a medium-severity weakness in D-Link DWR-X1820 routers where default administrative passwords are deterministically generated from the device's IMEI number. The vulnerability, published 2026-05-28, enables attackers with knowledge of the generation algorithm and physical access to the device (or its IMEI) to derive credentials without brute-force effort. No CISA KEV listing or known ransomware campaign use is recorded. D-Link addressed this in firmware version 1.00B16CP.

Vendor
D-Link Corporation
Product
DWR-X1820
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-28
Advisory published
2026-05-28
Advisory updated
2026-05-28

Who should care

Network administrators managing D-Link DWR-X1820 routers, security teams responsible for edge device hardening, and organizations with remote or branch office deployments using this equipment.

Technical summary

The D-Link DWR-X1820 router firmware generates default administrative passwords using a deterministic algorithm based on the device's IMEI number. Because the IMEI is physically printed on the device and often visible on packaging, an attacker with brief physical access or photographic documentation can derive valid credentials. The attack requires adjacent network access (AV:A) and high complexity (AC:H) per CVSS 4.0, reflecting the need for IMEI acquisition and algorithm knowledge. The vulnerability is classified under CWE-1391 (Use of Weak Credentials).

Defensive priority

medium

Recommended defensive actions

  • Inventory D-Link DWR-X1820 deployments and verify firmware version is 1.00B16CP or later
  • Replace default credentials with strong, unique passwords regardless of firmware version
  • Restrict administrative interface access to trusted management networks
  • Monitor for unauthorized access attempts to router management interfaces
  • Review device IMEI exposure in shipping materials, packaging, and physical security controls

Evidence notes

Evidence sources: NVD record (Awaiting Analysis status), CERT.PL advisory, and D-Link support page. CVSS 4.0 vector indicates attack vector adjacent (AV:A), high attack complexity (AC:H), and high confidentiality impact (VC:H). CWE-1391 (Use of Weak Credentials) is the primary weakness classification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-4377 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-4377

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-4377 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4377

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.