CVE-2017-14421: D-Link Dir-850l Firmware

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root access via a TELNET session.

Affected products

  • D-Link Dir-850l Firmware: up to and including fw208wwb02

Published 2017-09-13. Last modified 2026-06-17.