CVE-2022-36526
Description
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authentication bypass vulnerability in D-Link GO-RT-AC750 routers through the phpcgi_main function in cgibin allows unauthenticated remote access.
Vulnerability
An authentication bypass vulnerability exists in D-Link GO-RT-AC750 routers, specifically in firmware versions GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02. The flaw resides in the phpcgi_main function within the cgibin component. The vulnerability allows an unauthenticated attacker to bypass authentication mechanisms, as the phpcgi_main function does not properly validate credentials when processing certain requests [1].
Exploitation
An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the cgibin endpoint that invokes the phpcgi_main function. No authentication is required, and the attacker can be positioned remotely on the network. The attack does not require user interaction or any prior knowledge of credentials [1].
Impact
Successful exploitation grants the attacker unauthenticated access to administrative functions of the router, effectively bypassing the login mechanism. This can lead to full compromise of the device, including unauthorized configuration changes, denial of service, or further network attacks [1].
Mitigation
As of the publication date, D-Link has not released a security advisory or patched firmware version for this specific vulnerability. Users are advised to check the D-Link Security Bulletin page [1] for updates. No workarounds are documented in the available references. The devices may be approaching or past end-of-life status; consult the D-Link EOL policy [1] for further guidance.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/GO-RT-AC750description
- Range: revA_v101b03, revB_FWv200b02
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- d-link.commitrex_refsource_MISC
- drive.google.com/file/d/1ji5Ph6c-qgp0lBvbY8BZJjeqbju3VeK8/viewmitrex_refsource_MISC
- www.dlink.com/en/security-bulletin/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.