CVE-2026-6947

7.5

D-Link · DWM-222W USB Wi-Fi Adapter

The D-Link DWM-222W USB Wi-Fi Adapter contains a brute-force protection bypass vulnerability, which allows unauthenticated attackers to circumvent login attempt limits and compromise the device.

Executive summary

A critical authentication bypass flaw in the D-Link DWM-222W USB Wi-Fi Adapter allows unauthenticated attackers to perform brute-force attacks and gain administrative control over the device.

Vulnerability

The device fails to properly restrict excessive authentication attempts, enabling an unauthenticated attacker on an adjacent network to bypass login protections. This flaw allows the attacker to repeatedly attempt credentials until gaining unauthorized access.

Business impact

Successful exploitation of this vulnerability could lead to a complete loss of device confidentiality and integrity, as an attacker gaining control of a network adapter can potentially intercept or manipulate traffic. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to network security, potentially allowing unauthorized actors to pivot into the internal network environment.

Remediation

Immediate Action: Update the device firmware to version 1.02.00 or later as provided by the vendor.

Proactive Monitoring: Monitor device access logs for recurring failed login attempts or unusual administrative activity that may indicate a brute-force attack in progress.

Compensating Controls: Ensure the device is placed on an isolated management network and restrict access to the administrative interface to trusted IP addresses only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to prevent unauthorized device takeover. Administrators should verify the current firmware version of all deployed DWM-222W units and apply the 1.02.00 patch immediately to close the authentication bypass window and secure the device against brute-force attempts.

More D-Link CVEs

Sources