CVE-2018-6213: D-Link Dir-620 Firmware

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.

Affected products

  • D-Link Dir-620 Firmware: version 1.0.3 only; version 1.0.37 only; version 1.3.1 only; version 1.3.3 only; version 1.3.7 only; version 1.4.0 only; …

Published 2018-06-20. Last modified 2026-06-17.