CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability
D-Link Go-RT-AC750 GORTAC750revAv101b03 and GO-RT-AC750revBFWv200b02 are vulnerable to Buffer Overflow via cgibin, hnapmain,
Other sources
D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Users should discontinue product utilization of affected devices (D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02).
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-37055.
Which D-Link routers are affected by this vulnerability?
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are affected.
What is the severity of CVE-2022-37055?
The severity of CVE-2022-37055 is critical with a CVSS score of 9.8.
How can I fix the vulnerability?
To fix the vulnerability, update the firmware of the affected D-Link routers to the latest version available.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the provided references: [link1](https://drive.google.com/file/d/1hmIk0jQoex4QDyjIUg_6yxi-J6ROCh8S/view?usp=sharing) [link2](https://www.dlink.com/en/security-bulletin/)