VendorsD-Linkgo-rt-ac750_firmware101b03
Vulnerabilities

D-Link go-rt-ac750 Firmware 101b03

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-22853
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
Published 2024-02-06 · Modified
9.8EPSS 0.048
CVE-2023-48842
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.
Published 2023-12-01 · Modified
9.8EPSS 0.037
CVE-2022-36523
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
Published 2022-08-15 · Modified
9.8EPSS 0.022
CVE-2022-36525
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.
Published 2022-08-15 · Modified
9.8EPSS 0.016
CVE-2024-22852
D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.
Published 2024-02-06 · Modified
9.8EPSS 0.011
CVE-2024-22916
In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.
Published 2024-01-16 · Modified
9.8EPSS 0.010
CVE-2024-27683
D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.
Published 2024-03-21 · Analyzed
9.8EPSS 0.009
CVE-2022-36526
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.
Published 2022-08-15 · Modified
7.5EPSS 0.012
CVE-2022-36524
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
Published 2022-08-15 · Modified
7.5EPSS 0.009
CVE-2024-27684
A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Published 2024-03-04 · Analyzed
6.1EPSS 0.005