Executive brief
The D-Link DWR-X1820 router uses a predictable default password derived from the device's unique IMEI number. Because the device does not force users to change this password, an attacker who obtains the IMEI can gain unauthorized access to the router's management interface. This could allow an attacker to monitor network traffic or change device settings, potentially compromising the security of the connected home or office network.
Technical details
The D-Link DWR-X1820 router is vulnerable to the use of weak credentials (CWE-1391). The device generates its default administrative password using a predictable algorithm based on the hardware IMEI number. Furthermore, the firmware does not implement a mandatory password change upon initial setup. An attacker within wireless range or on the local network who obtains the device's IMEI can calculate the password and gain full administrative access. The issue affects versions 1.00B14CP through 1.00B16CP and is addressed in version 1.00B16CP.
Affected products
- D-Link DWR-X1820 1.00B14CP through 1.00B16CP
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory: Advisory published by CERT.PL and NVD
- 2026-05-28: patched: Fixed in version 1.00B16CP