CISA Warns of D-Link Routers Buffer Overflow Vulnerability Exploited in Attacks
A critical buffer overflow vulnerability affecting D-Link routers has been added to the CISA catalog of Known Exploited Vulnerabilities. This indicates active exploitation of the vulnerability in the wild.
A critical buffer overflow vulnerability affecting D-Link routers has been added to the CISA catalog of Known Exploited Vulnerabilities. This indicates active exploitation of the vulnerability in the wild.
The flaw, tracked as CVE-2022-37055, poses severe risks to organizations and enterprise networks that rely on affected D-Link networking equipment. The vulnerability arises from improper memory management in D-Link routers, allowing unauthenticated attackers to trigger a buffer overflow condition.
Field Details
CVE ID CVE-2022-37055
Vulnerability Type Buffer Overflow
Affected Product D-Link Routers
A critical buffer overflow vulnerability affecting D-Link routers has been added to the CISA catalog of Known Exploited Vulnerabilities.
CVSS v3.1 Score 9.8 (Critical)
Attack Vector Network
CWE Classification CWE-120: Buffer Copy without Checking Size of Input
Product Status End-of-Life (EoL) / End-of-Service (EoS)
Successful exploitation allows adversaries to execute arbitrary code with device-level privileges, potentially compromising network traffic, system integrity, and data confidentiality. The vulnerability significantly impacts confidentiality, integrity, and availability.
The advisory highlights the risk associated with D-Link products that have reached end-of-life or end-of-service status, as they may not receive security updates, leaving limited remediation options.
CISA issued the advisory on December 8, 2025, with a mandatory remediation deadline of December 29, 2025. Organizations are urged to act promptly to address this threat. Recommended actions include:
Apply vendor-supplied patches immediately where available. Discontinue the use of unsupported D-Link equipment. Conduct inventory audits to identify all D-Link routers within the infrastructure. Implement network segmentation controls to reduce lateral movement risks. Enforce firewall rules to limit administrative access to routers. Enhance network monitoring to detect suspicious device behavior. Follow applicable CISA Binding Operational Directive 22-01 guidance for cloud service deployments, particularly for critical infrastructure environments.
Organizations unable to apply patches or discontinue the use of vulnerable products should implement enhanced monitoring and access restrictions while planning equipment replacement timelines.
Based on reporting by Cyber Security News.
