VYPR
Unrated severityNVD Advisory· Published Aug 15, 2022· Updated Aug 3, 2024

CVE-2022-36525

CVE-2022-36525

Description

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in the authentication CGI of D-Link Go-RT-AC750 routers allows remote unauthenticated attackers to crash the device or achieve code execution.

Vulnerability

A buffer overflow vulnerability exists in the authenticationcgi_main function of D-Link Go-RT-AC750 routers running firmware versions GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 [1]. The bug occurs when handling input data, and no authentication or prior access is required to reach the vulnerable code path [1].

Exploitation

An attacker can send a specially crafted HTTP request to the router's authentication CGI endpoint without any prior authentication [1]. No user interaction or local access is needed; the attacker only requires network connectivity to the device [1].

Impact

Successful exploitation can lead to a buffer overflow, potentially causing a denial of service (crash) or arbitrary code execution on the device [1]. Compromise could grant the attacker full control over the router, enabling further network attacks [1].

Mitigation

No fix or updated firmware has been released by D-Link as of the publication date (2022-08-15) [1]. Users are advised to monitor the vendor's security bulletin page for future updates [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/Go-RT-AC750description
  • Range: v101b03 and v200b02

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.