CVE-2026-42372
D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell with full administrative control. The device has reached End-of-Life (EOL) and will not receive patches.
Published:May 4, 2026
Last Modified:May 6, 2026
EPS:May 4, 2026
EPSS Score:0.00042
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
D-link
Product
Dir-605l Firmware
D-link
Dir-605l Firmware
Vendor
Dlink
Product
Dir-605l
Dlink
Dir-605l
Vendor
Dlink
Product
Dir-605l Firmware
Dlink
Dir-605l Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
