CVE-2018-10968: D-Link Dir-550a Firmware

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable devices, aka a backdoor access vulnerability.

Affected products

  • D-Link Dir-550a Firmware: up to and including 2.10kr
  • D-Link Dir-604m Firmware: up to and including 2.10kr

Published 2018-05-18. Last modified 2026-06-17.