CVE-2018-20675: D-Link Dir-822-Us Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authentication bypass.

Affected products

  • D-Link Dir-822-Us Firmware: up to and including 3.10b06
  • D-Link Dir-822 Firmware: up to and including 3.10b06
  • D-Link Dir-850l Firmware: up to and including 1.21b07; up to and including 2.21b01; version 2.22b02 only
  • D-Link Dir-880l Firmware: up to and including 1.07.b08; version 1.20b01 only

Published 2019-01-09. Last modified 2026-06-17.