← Vulnerability feed

Vulnerability record · CVE-2022-37055 · published 28 August 2022

CVE-2022-37055: D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_main

Dlink · Go Rt Ac750 Firmware

D-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The flaw is remotely exploitable without authentication or user interaction, and the vendor has published a security advisory. Because the device is a network edge router, successful exploitation can compromise the whole network behind it.

9.8 CVSS 3.1 Critical CISA KEV since 8 Dec 2025 EPSS 56% · top 1.0% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated remote buffer overflow on an edge router, listed in CISA KEV with high EPSS and evidence of in-the-wild exploitation.

What it is

D-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The flaw is remotely exploitable without authentication or user interaction, and the vendor has published a security advisory. Because the device is a network edge router, successful exploitation can compromise the whole network behind it.

Impact

An unauthenticated remote attacker can overflow the buffer to corrupt memory and potentially achieve arbitrary code execution on the router. That yields full control of the device, including its traffic and any credentials or sessions passing through it.

Attack surface

Reached over the network through the router's HTTP/cgibin HNAP interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

CVE-2022-37055 is listed in CISA KEV with a due date of 2025-12-29, and EPSS gives a 30-day probability of 0.555 (99th percentile). References include an exploit-tagged third-party advisory and a Fortiguard outbreak alert, indicating active exploitation in the wild.

What to do

  • Apply the vendor fix per D-Link security advisory SAP10308; if no patch exists for your revision, discontinue use of the device as CISA directs.
  • Replace end-of-life Go-RT-AC750 units that no longer receive firmware updates.
  • Disable or block remote access to the router's web/HNAP management interface from the WAN; restrict administration to the LAN.
  • Segment or isolate the router from sensitive internal networks until it is patched or replaced.
  • Monitor vendor and CISA guidance for updated firmware or replacement recommendations.

Detection

  • Inspect router and perimeter logs for anomalous requests to /cgibin or HNAP endpoints, especially oversized or malformed payloads.
  • Alert on unexpected router reboots, crashes, or process restarts that could indicate a failed overflow attempt.
  • Monitor for new outbound connections or configuration changes originating from the router itself.
  • Use network monitoring to detect exploitation attempts against D-Link Go-RT-AC750 devices on the network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-37055 to the Known Exploited Vulnerabilities catalog on 8 December 2025 as "D-Link Routers Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 29 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-37055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27683Dlink go-rt-ac750 firmware stack-based buffer overflow vulnerabilityD-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to …EPSS 0.88%9.8CVE-2024-22852Dlink go-rt-ac750 firmware out-of-bounds write vulnerabilityD-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers …EPSS 1.1%9.8CVE-2024-22853Dlink go-rt-ac750 firmware hard-coded credentials vulnerabilityD-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root acces…EPSS 4.8%9.8CVE-2024-22916Dlink go-rt-ac750 firmware out-of-bounds write vulnerabilityIn D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.EPSS 0.99%9.8CVE-2023-48842Dlink go-rt-ac750 firmware command injection vulnerabilityD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.EPSS 3.7%9.8CVE-2023-34800Dlink go-rt-ac750 firmware os command injection vulnerabilityD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.EPSS 29%9.8CVE-2023-26822Dlink go-rt-ac750 firmware command injection vulnerabilityD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.EPSS 3.4%9.8CVE-2022-37056Dlink go-rt-ac750 firmware os command injection vulnerabilityD-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2022-37055), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.