What this actually is.
Technical background, root cause, and affected surface.
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration.
- Vendor
- DLink
- Affected Product
- COVR-3902_REVA_ROUTER_FIRMWARE_v1.01B0
- CVE
- CVE-2018-20432
- Securin ID
- 2018-CSW-02-1019
- Status
- Fixed
- Date
- December 5, 2018
- Severity
- Critical
- CVSS Score
- 9.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-798
From one request
to root shell.
Reproduced in a sandboxed environment. Requires only LAN or WiFi adjacency.
What an attacker does to you.
Post-exploitation outcomes mapped to CVSS impact metrics.
An unauthenticated attacker gains privileged access to the router, and to extract sensitive data or modify the configuration.
Fix it. In this order.
A runbook, not a checklist. Sequence matters — assume compromise before you act.
Download and apply the relevant from the vendor:
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10109
disclose@securin.ioVendors moved in days.
Attackers in hours.
Reconstructed from vendor advisories, CISA bulletins, and Securin research records.
Discovered in Dlink.
Timeline recorded · Disclosure coordinated by Securin
Cite, verify, go deeper.
Primary sources — NVD, CISA KEV, and machine-readable IoC feed.