Vulnerability record · CVE-2022-37055 · published 28 August 2022
CVE-2022-37055: D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_main
Dlink · Go Rt Ac750 Firmware
D-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The flaw is remotely exploitable without authentication or user interaction, and the vendor has published a security advisory. Because the device is a network edge router, successful exploitation can compromise the whole network behind it.
Description
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated remote buffer overflow on an edge router, listed in CISA KEV with high EPSS and evidence of in-the-wild exploitation.
What it is
D-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The flaw is remotely exploitable without authentication or user interaction, and the vendor has published a security advisory. Because the device is a network edge router, successful exploitation can compromise the whole network behind it.
Impact
An unauthenticated remote attacker can overflow the buffer to corrupt memory and potentially achieve arbitrary code execution on the router. That yields full control of the device, including its traffic and any credentials or sessions passing through it.
Attack surface
Reached over the network through the router's HTTP/cgibin HNAP interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
CVE-2022-37055 is listed in CISA KEV with a due date of 2025-12-29, and EPSS gives a 30-day probability of 0.555 (99th percentile). References include an exploit-tagged third-party advisory and a Fortiguard outbreak alert, indicating active exploitation in the wild.
What to do
- Apply the vendor fix per D-Link security advisory SAP10308; if no patch exists for your revision, discontinue use of the device as CISA directs.
- Replace end-of-life Go-RT-AC750 units that no longer receive firmware updates.
- Disable or block remote access to the router's web/HNAP management interface from the WAN; restrict administration to the LAN.
- Segment or isolate the router from sensitive internal networks until it is patched or replaced.
- Monitor vendor and CISA guidance for updated firmware or replacement recommendations.
Detection
- Inspect router and perimeter logs for anomalous requests to /cgibin or HNAP endpoints, especially oversized or malformed payloads.
- Alert on unexpected router reboots, crashes, or process restarts that could indicate a failed overflow attempt.
- Monitor for new outbound connections or configuration changes originating from the router itself.
- Use network monitoring to detect exploitation attempts against D-Link Go-RT-AC750 devices on the network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-37055 to the Known Exploited Vulnerabilities catalog on 8 December 2025 as "D-Link Routers Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 29 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://drive.google.com/file/d/1hmIk0jQoex4QDyjIUg_6yxi-J6ROCh8S/view?usp=sharing | ExploitPatchThird Party Advisory |
| https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308 | Vendor Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
| https://drive.google.com/file/d/1hmIk0jQoex4QDyjIUg_6yxi-J6ROCh8S/view?usp=sharing | ExploitPatchThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37055 | US Government Resource |
| https://www.fortiguard.com/outbreak-alert/d-link-multiple-devices-attack | Third Party Advisory |
Track CVE-2022-37055 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37055), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.