Junglewise Threat Intelligence

CVE-2026-42376: D-Link DIR-456U hardcoded telnet backdoor

CVE-2026-42376 · Severity: critical · CVSS 9.8 · Published 2026-05-04

Vendors: Dlink, D-Link.

Executive brief

The D-Link DIR-456U router contains a permanent security backdoor that allows anyone on the local network to take full control of the device. By using a secret, built-in username and password, an attacker can access the router's administrative functions without your permission. Because this product is at its end-of-life, the manufacturer will not be providing any security updates to fix this issue. Using this device poses a significant risk to your network security and privacy.

Technical details

The D-Link DIR-456U Hardware Revision A1 contains a hardcoded telnet backdoor (CWE-798) originating from its ODM, Alpha Networks. The device unconditionally executes a boot script (/etc/init0.d/S80telnetd.sh) that starts a telnet daemon with a custom login binary. This binary validates credentials against a hardcoded username ('Alphanetworks') and a static password ('whdrv01_dlob_dir456U') stored in the firmware. An attacker on the local network (LAN or WLAN) can connect to TCP port 23 to obtain a root shell with full administrative privileges. As the device is End-of-Life (EOL), no patches are available, and the manufacturer recommends replacing the hardware.

Affected products

  • D-Link DIR-456U Hardware Revision A1 (All firmware versions)

Timeline

  • 2026-04-20: other: Vulnerability identified and validated via QEMU
  • 2026-04-20: other: Reported to vendor
  • 2026-04-21: other: Vendor confirmed EOL status; no fix will be issued
  • 2026-05-04: advisory: Public advisory and CVE published

References