CVE-2022-36524
Description
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
D-Link GO-RT-AC750 routers have static default credentials for telnet, allowing remote attackers to gain root access.
Vulnerability
The D-Link GO-RT-AC750 router models GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 contain a static default credential vulnerability in the telnet service. The file /etc/init0.d/S80telnetd.sh stores hardcoded credentials that are not changed during initial setup, enabling unauthenticated remote access to the device's command shell.
Exploitation
An attacker with network access to the router's telnet port (typically TCP 23) can connect and log in using the default credentials stored in the script. No prior authentication or user interaction is required. The attacker simply initiates a telnet session and supplies the hardcoded username and password.
Impact
Successful exploitation grants the attacker a root-level shell on the device. This allows full control over the router, including the ability to modify configuration, intercept network traffic, launch further attacks on the local network, and persist access.
Mitigation
As of the publication date (2022-08-15), D-Link has not released a firmware update to address this vulnerability. The affected models may be end-of-life (EOL). Users should disable the telnet service if possible, restrict network access to the device, or replace the router with a supported model. Refer to the D-Link security bulletin [1] for general guidance.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/GO-RT-AC750description
- Range: v101b03 (revA) and FWv200b02 (revB)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- d-link.commitrex_refsource_MISC
- drive.google.com/file/d/1WNKrDUbYfSWbSve9ONILkLY6dbM8I7hh/viewmitrex_refsource_MISC
- www.dlink.com/en/security-bulletin/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.