CVE-2022-37055
dlink go-rt-ac750 firmware
Published 28 Aug 2022 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 8 Dec 2025, with a remediation deadline of 29 Dec 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
References
- drive.google.com/file/d/1hmIk0jQoex4QDyjIUg_6yxi-J6ROCh8S/view?usp=sharing · Exploit, Patch, Third Party Advisory
- supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308 · Vendor Advisory
- www.dlink.com/en/security-bulletin/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37055 · US Government Resource
- www.fortiguard.com/outbreak-alert/d-link-multiple-devices-attack · Third Party Advisory