CVE-2018-18907: D-Link Dir-850l Firmare

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.

Affected products

  • D-Link Dir-850l Firmare: before 1.21b07 (fixed in 1.21b07)

Published 2022-06-16. Last modified 2026-06-17.