CVE-2026-42372
8.8D-Link · DIR-605L Hardware Revision A1
D-Link DIR-605L Revision A1 contains a hardcoded telnet backdoor allowing full administrative root access to network attackers.
Executive summary
D-Link DIR-605L Hardware Revision A1 contains a hardcoded telnet backdoor, exposing the affected device to complete administrative compromise by network attackers.
Vulnerability
This vulnerability is caused by the use of hardcoded credentials (CWE-798) in the device telnet daemon startup script, which accepts static login values and can be exploited by an unauthenticated attacker on the local network.
Business impact
A successful exploit grants an attacker a root shell with full administrative control over the affected hardware, leading to potential total network compromise and data interception. The CVSS score of 8.8 reflects the severity of this access level, though the risk is constrained by requiring local network adjacency.
Remediation
Immediate Action: Disconnect the affected device from the network immediately, as the hardware has reached End-of-Life status and will not receive vendor patches.
Proactive Monitoring: Monitor network perimeter logs and internal segment traffic for unauthorized telnet connections and brute force authentication attempts.
Compensating Controls: Implement network segmentation and firewall rules to strictly isolate the vulnerable router from untrusted network segments.
Exploitation status
Public Exploit Available: Yes, a published PoC exists, cited in the researcher advisory at Securin.
Analyst recommendation
Given that the affected product is End-of-Life and will not receive security patches from the vendor, immediate hardware replacement is the only effective remediation. Organizations must retire the vulnerable device and transition to a supported hardware model to eliminate the persistent risk of unauthorized administrative access.
More D-Link CVEs
Sources
Originally found and disclosed by Arjun Basnet From Securin Labs, per the CVE Program record.