Junglewise Threat Intelligence

CVE-2026-6947: D-Link DWM-222W brute-force protection bypass

CVE-2026-6947 · Severity: high · CVSS 7.5 · Published 2026-04-24

Vendors: D-Link.

Executive brief

The D-Link DWM-222W USB Wi-Fi adapter, a device used to provide wireless connectivity to computers, contains a security flaw that allows attackers to bypass login protections. By circumventing limits on failed login attempts, an unauthorized person on the same network could repeatedly guess passwords until they gain full control over the device. This could lead to unauthorized access to network settings or the disruption of internet connectivity.

Technical details

The D-Link DWM-222W USB Wi-Fi adapter is vulnerable to a brute-force protection bypass (CWE-307) in its authentication mechanism. The device fails to properly enforce or restrict excessive authentication attempts, allowing an unauthenticated attacker with network access to bypass login rate limits. By automating password guessing without being locked out, an attacker can eventually identify valid credentials and gain administrative control over the device. This vulnerability affects firmware versions prior to 1.02.00 and can be mitigated by updating to version 1.02.00 or later.

Affected products

  • D-Link DWM-222W USB Wi-Fi Adapter before 1.02.00

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory
  • 2026-04-24: patched: Firmware version 1.02.00 released to address the issue.

References