← Vulnerability feed

Vulnerability record · CVE-2022-37056 · published 28 August 2022

CVE-2022-37056: Dlink go-rt-ac750 firmware os command injection vulnerability

Dlink · Go Rt Ac750 Firmware

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

9.8 CVSS 3.1 Critical EPSS 10% · top 4.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-37056 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-37055D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_mainD-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The f…KEVEPSS 56%analysed9.8CVE-2024-27683Dlink go-rt-ac750 firmware stack-based buffer overflow vulnerabilityD-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to …EPSS 0.88%9.8CVE-2024-22852Dlink go-rt-ac750 firmware out-of-bounds write vulnerabilityD-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers …EPSS 1.1%9.8CVE-2024-22853Dlink go-rt-ac750 firmware hard-coded credentials vulnerabilityD-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root acces…EPSS 4.8%9.8CVE-2024-22916Dlink go-rt-ac750 firmware out-of-bounds write vulnerabilityIn D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.EPSS 0.99%9.8CVE-2023-48842Dlink go-rt-ac750 firmware command injection vulnerabilityD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.EPSS 3.7%9.8CVE-2023-34800Dlink go-rt-ac750 firmware os command injection vulnerabilityD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.EPSS 29%9.8CVE-2023-26822Dlink go-rt-ac750 firmware command injection vulnerabilityD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2022-37056), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.