VYPR
Unrated severityNVD Advisory· Published Aug 15, 2022· Updated Aug 3, 2024

CVE-2022-36523

CVE-2022-36523

Description

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link Go-RT-AC750 firmware versions are vulnerable to command injection via /htdocs/upnpinc/gena.php, allowing unauthenticated remote code execution.

Vulnerability

The D-Link Go-RT-AC750 routers running firmware versions GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 contain a command injection vulnerability in the /htdocs/upnpinc/gena.php script. The vulnerability allows an attacker to inject arbitrary commands through crafted HTTP requests to this endpoint.

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable gena.php endpoint without requiring authentication. The attacker only needs network access to the device. The exact request structure is not publicly detailed, but command injection flaws typically involve inserting shell metacharacters into parameters processed by the script.

Impact

Successful exploitation permits an attacker to execute arbitrary commands on the affected device with root privileges. This can lead to full compromise of the router, including unauthorized access to network traffic, modification of device settings, and potential lateral movement within the network.

Mitigation

As of publication, no official firmware update has been released to address this vulnerability. The device may be approaching end-of-life (EOL) status; D-Link's security bulletin [1] should be monitored for any future patches. Users are advised to restrict network access to the router's administrative interface and consider replacing the device if it is no longer supported.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.