CVE-2022-37055

9.5 CISA KEV

D-Link · Go-RT-AC750

D-Link Go-RT-AC750 routers contain a buffer overflow vulnerability in the cgibin and hnap_main functions that allows for unauthenticated remote code execution.

Executive summary

This critical buffer overflow vulnerability in D-Link Go-RT-AC750 routers is currently being exploited in the wild to facilitate unauthorized remote code execution and botnet propagation.

Vulnerability

The flaw resides in the cgibin and hnap_main components of the router firmware. It allows an unauthenticated remote attacker to trigger a buffer overflow, potentially leading to full system compromise.

Business impact

The CVSS score of 9.5 indicates a critical risk to business operations, primarily due to the potential for total system takeover. Successful exploitation can result in complete loss of confidentiality, integrity, and availability, allowing attackers to pivot into internal networks, intercept traffic, or utilize the compromised device as part of a malicious botnet.

Remediation

Immediate Action: Because these devices are end of life, the primary recommendation is to retire and replace the affected hardware immediately.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from internal router management interfaces and inspect system logs for repeated crashes or unauthorized configuration changes.

Compensating Controls: If immediate replacement is impossible, isolate the affected devices from the public internet using a restrictive firewall policy and disable remote administration features until the hardware can be decommissioned.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exploit is available via the technical research documentation provided in the vendor security advisory.

Analyst recommendation

Given the confirmed active exploitation and the critical nature of this vulnerability, organizations must treat this as an emergency. Since these devices are end of life and lack security updates, they represent a permanent and unpatchable risk to the network. Immediate decommissioning of the affected hardware is the only reliable method to mitigate this threat.

More D-Link CVEs

Sources