VYPR
Unrated severityNVD Advisory· Published Aug 15, 2022· Updated Aug 3, 2024

CVE-2022-36526

CVE-2022-36526

Description

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authentication bypass vulnerability in D-Link GO-RT-AC750 routers through the phpcgi_main function in cgibin allows unauthenticated remote access.

Vulnerability

An authentication bypass vulnerability exists in D-Link GO-RT-AC750 routers, specifically in firmware versions GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02. The flaw resides in the phpcgi_main function within the cgibin component. The vulnerability allows an unauthenticated attacker to bypass authentication mechanisms, as the phpcgi_main function does not properly validate credentials when processing certain requests [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the cgibin endpoint that invokes the phpcgi_main function. No authentication is required, and the attacker can be positioned remotely on the network. The attack does not require user interaction or any prior knowledge of credentials [1].

Impact

Successful exploitation grants the attacker unauthenticated access to administrative functions of the router, effectively bypassing the login mechanism. This can lead to full compromise of the device, including unauthorized configuration changes, denial of service, or further network attacks [1].

Mitigation

As of the publication date, D-Link has not released a security advisory or patched firmware version for this specific vulnerability. Users are advised to check the D-Link Security Bulletin page [1] for updates. No workarounds are documented in the available references. The devices may be approaching or past end-of-life status; consult the D-Link EOL policy [1] for further guidance.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/GO-RT-AC750description
  • Range: revA_v101b03, revB_FWv200b02

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.