VYPR
Unrated severityNVD Advisory· Published Feb 6, 2024· Updated May 15, 2025

CVE-2024-22852

CVE-2024-22852

Description

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in D-Link Go-RT-AC750 allows attackers to enable telnet service via crafted payload.

Vulnerability

The D-Link Go-RT-AC750 router firmware version GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow vulnerability in the genacgi_main function. This bug can be triggered by a specially crafted payload, enabling arbitrary code execution or service manipulation. [1]

Exploitation

An attacker can exploit this vulnerability by sending a crafted payload to the vulnerable function. No authentication is required if the service is exposed; however, network access to the device is necessary. The payload triggers a buffer overflow, allowing the attacker to control execution flow.

Impact

Successful exploitation results in the attacker enabling telnet service on the device, which can lead to full remote control and further compromise of the device and network. The vulnerability has a high severity (CVSS score not provided) but could allow complete device takeover.

Mitigation

D-Link has not released a firmware patch as of the publication date (2024-02-06). Users are advised to check the D-Link security bulletin [1] for updates. The device may be end-of-life (EOL); consider replacing it if no patch is provided.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.