9.8

CVE-2022-37055

Warnung
Medienbericht
Exploit
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dlink ≫ Go-rt-ac750 Firmware Version 2.00b02
   Dlink ≫ Go-rt-ac750 Version revision_b
Dlink ≫ Go-rt-ac750 Firmware Version 1.01b03
   Dlink ≫ Go-rt-ac750 Version revision_a

08.12.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

D-Link Routers Buffer Overflow Vulnerability

Schwachstelle

D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 55.53% 0.99
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
17.08.2026 13:00
https://www.dlink.com/en/security-bulletin/
Vendor Advisory
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308
Vendor Advisory
https://drive.google.com/file/d/1hmIk0jQoex4QDyjIUg_6yxi-J6ROCh8S/view?usp=sharing
Patch
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37055
US Government Resource
https://www.fortiguard.com/outbreak-alert/d-link-multiple-devices-attack
Third Party Advisory