Dlink
Dlink Go-rt-ac750 Firmware: vulnerabilidades y CVE
Dlink Go-rt-ac750 Firmware tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 12 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas12
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-37055 | Crítica (9.8) | 56% | ⚠ Explotación activa | 28 ago 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-27683 | Crítica (9.8) | 0.88% | — | 11 abr 2024 | D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify. |
| CVE-2024-27684 | Media (6.1) | 0.51% | — | 4 mar 2024 | A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url… |
| CVE-2024-22853 | Crítica (9.8) | 4.8% | — | 6 feb 2024 | D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session. |
| CVE-2024-22852 | Crítica (9.8) | 1.1% | — | 6 feb 2024 | D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload. |
| CVE-2024-22916 | Crítica (9.8) | 0.99% | — | 16 ene 2024 | In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow. |
| CVE-2023-48842 | Crítica (9.8) | 3.7% | — | 1 dic 2023 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi. |
| CVE-2023-34800 | Crítica (9.8) | 29% | — | 15 jun 2023 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. |
| CVE-2023-26822 | Crítica (9.8) | 3.4% | — | 1 abr 2023 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main. |
| CVE-2022-37056 | Crítica (9.8) | 10% | — | 28 ago 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main, |
| CVE-2022-37055 | Crítica (9.8) | 56% | ⚠ Explotación activa | 28 ago 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, |
| CVE-2022-37057 | Crítica (9.8) | 26% | — | 28 ago 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main. |
| CVE-2022-36526 | Alta (7.5) | 1.2% | — | 15 ago 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin. |
| CVE-2022-36525 | Crítica (9.8) | 1.6% | — | 15 ago 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main. |
| CVE-2022-36524 | Alta (7.5) | 0.86% | — | 15 ago 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh. |
| CVE-2022-36523 | Crítica (9.8) | 2.2% | — | 15 ago 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.