CRITICAL

CVE-2022-37055

Dlink Go Rt Ac750 Firmware 2022-08-28 CVSS v3.1
CVSS
9.8
KEV

Description

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

Summary dbcve.org

Buffer overflow vulnerabilities exist in the cgibin and hnap_main components of D-Link Go-RT-AC750 routers (hardware revisions A v101b03 and B FWv200b02). These unauthenticated, network-reachable CGI/HNAP endpoints can be abused by remote attackers to overflow buffers, potentially leading to arbitrary code execution or denial of service. The CVSS 9.8 score reflects the critical nature of remote, unauthenticated buffer overflow on internet-exposed router management interfaces.

Mitigation

Upgrade affected routers to the latest vendor-supplied firmware if available; if no patch is provided (these revisions are likely end-of-life), replace the devices, restrict remote management access, and segment the routers from untrusted networks.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-120 Classic Buffer Overflow

EPSS Score

55.53%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE