Executive brief
The D-Link DIR-456U router contains a permanent security backdoor that allows anyone on the local network to take full control of the device. By using a secret, built-in username and password, an attacker can access the router's administrative functions without your permission. Because this product is at its end-of-life, the manufacturer will not be providing any security updates to fix this issue. Using this device poses a significant risk to your network security and privacy.
Technical details
The D-Link DIR-456U Hardware Revision A1 contains a hardcoded telnet backdoor (CWE-798) originating from its ODM, Alpha Networks. The device unconditionally executes a boot script (/etc/init0.d/S80telnetd.sh) that starts a telnet daemon with a custom login binary. This binary validates credentials against a hardcoded username ('Alphanetworks') and a static password ('whdrv01_dlob_dir456U') stored in the firmware. An attacker on the local network (LAN or WLAN) can connect to TCP port 23 to obtain a root shell with full administrative privileges. As the device is End-of-Life (EOL), no patches are available, and the manufacturer recommends replacing the hardware.
Affected products
- D-Link DIR-456U Hardware Revision A1 (All firmware versions)
Timeline
- 2026-04-20: other: Vulnerability identified and validated via QEMU
- 2026-04-20: other: Reported to vendor
- 2026-04-21: other: Vendor confirmed EOL status; no fix will be issued
- 2026-05-04: advisory: Public advisory and CVE published