CVE-2022-37055
Description
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
Summary dbcve.org
Buffer overflow vulnerabilities exist in the cgibin and hnap_main components of D-Link Go-RT-AC750 routers (hardware revisions A v101b03 and B FWv200b02). These unauthenticated, network-reachable CGI/HNAP endpoints can be abused by remote attackers to overflow buffers, potentially leading to arbitrary code execution or denial of service. The CVSS 9.8 score reflects the critical nature of remote, unauthenticated buffer overflow on internet-exposed router management interfaces.
Mitigation
Upgrade affected routers to the latest vendor-supplied firmware if available; if no patch is provided (these revisions are likely end-of-life), replace the devices, restrict remote management access, and segment the routers from untrusted networks.