# CVE-2026-4377

## Summary

- **CVE ID:** CVE-2026-4377
- **Severity:** MEDIUM
- **CVSS Score:** 6 (CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1391
- **Published:** May 28, 2026
- **Last Modified:** May 28, 2026

## Description

Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number.

This issue was fixed in version 1.00B16CP.

## Affected Products

- D-Link Corporation — DWR-X1820 (1.00B14CP)

## References

- [CNA](https://cert.pl/posts/2026/05/CVE-2026-4377)
- [CNA](https://www.dlink.com/pl/pl/products/dwr-1820-cp#support)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._