Hardcoded Telnet Backdoor in D-Link DIR-456U A1 Device
CVE-2026-42376
9.8CRITICAL
What is CVE-2026-42376?
The D-Link DIR-456U A1 device has a serious security flaw characterized by a hardcoded telnet backdoor. This backdoor allows an unauthenticated attacker on the local network to gain root access to the device. The device initializes a telnet daemon during boot, exposing a hardcoded username and password. This poses a significant risk, considering the device has reached End-of-Life status and will not receive any patches to mitigate this vulnerability.
Affected Version(s)
DIR-456U Firmware MIPS32 Little-Endian A1