CVE-2022-37055 is a critical buffer overflow vulnerability affecting D-Link GO-RT-AC750 routers (firmware versions GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02) through the cgibin and hnap_main components. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary code remotely with high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion. While no public exploit code is readily available on platforms like Metasploit or ExploitDB, its active exploitation and high risk score of 100/100 necessitate immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.00b02CPE matchmatch criteria | cpe:2.3:o:dlink:go-rt-ac750_firmware:2.00b02:*:*:*:*:*:*:* | ||
1.01b03CPE matchmatch criteria | cpe:2.3:o:dlink:go-rt-ac750_firmware:1.01b03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.