Executive brief
A critical security vulnerability has been identified in certain D-Link GO-RT-AC750 routers, which are used to provide wireless internet connectivity in homes and small offices. This flaw allows an attacker to remotely take control of the device without needing a password, potentially leading to the theft of sensitive data, monitoring of internet traffic, or complete service disruption. Because these devices are considered end-of-life, the manufacturer may not provide further security updates, and users are strongly advised to replace the affected hardware.
Technical details
A classic buffer overflow (CWE-120) exists in the D-Link GO-RT-AC750 router within the 'cgibin' and 'hnap_main' components. The vulnerability is caused by insufficient input validation when processing network requests, allowing a remote, unauthenticated attacker to trigger a buffer overflow via the network. Successful exploitation can lead to arbitrary code execution with high privileges, compromising the confidentiality, integrity, and availability of the device. This vulnerability has been observed in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog. Affected devices are end-of-life (EoL), and users are advised to discontinue use.
Affected products
- D-Link GO-RT-AC750 firmware 1.01b03 (Rev A), 2.00b02 (Rev B)
Timeline
- 2022-08-28: disclosed: Initial NVD publication
- 2025-12-08: kev added: Added to CISA Known Exploited Vulnerabilities catalog