Two D-Link router vulnerabilities, both confirmed exploited and both affecting end-of-life or end-of-service hardware, landed in CISA's KEV catalogue within a five-month span — and both come with the same requiredAction language: apply mitigations where possible, or "discontinue use of the product if mitigations are unavailable," because for these specific devices, no further vendor patch is coming.
| CVE | CVSS | Product | Added to KEV |
|---|---|---|---|
| CVE-2022-37055 | 9.8 | Go-RT-AC750 routers (buffer overflow) | 8 Dec 2025 |
| CVE-2025-29635 | 7.2 | DIR-823X (command injection) | 24 Apr 2026 |
Two different endpoints, one common outcome: full device compromise on hardware that will never be patched
CVE-2022-37055 is about as severe as a CVSS score gets: a 9.8, unauthenticated, network-reachable buffer overflow in the Go-RT-AC750's cgibin/hnap_main handling, per NVD. HNAP — the Home Network Administration Protocol — has an unusually long and well-documented history of vulnerabilities across multiple router vendors, and this entry continues that pattern on D-Link's specific implementation. CVE-2025-29635 is narrower in one sense — NVD specifies it "allows an authorized attacker" to execute arbitrary commands via a POST request to /goform/set_prohibiting on the DIR-823X — but the KEV description is explicit that this campaign has already been observed: Akamai's own referenced research is titled "CVE-2025-29635 Mirai campaign targets D-Link devices," meaning this isn't theoretical exploitation, it's an active botnet recruitment vector as of the vulnerability's addition to KEV in April 2026.
Both entries carry the same KEV note verbatim: "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization." That phrasing is CISA's way of acknowledging that for a meaningful share of the affected install base, there simply is no patch to apply — the vendor has moved on, and the only real mitigation is replacement or, at minimum, removing the device from any network path an attacker could reach.
Why consumer and small-business routers are a durable botnet resource, not a one-time story
The pattern connecting these two CVEs — and a huge share of D-Link's KEV history more broadly — is that consumer-grade routers make exceptionally good botnet infrastructure for exactly the reasons that make them bad to defend: they are rarely monitored, rarely patched by their owners even when a fix exists, frequently sit at the network edge with a public IP, and once compromised, provide a stable, always-on foothold that can sit unnoticed for years. The Mirai family of botnets, explicitly named in the Akamai research covering CVE-2025-29635, has built its entire operating model around exactly this reality: identify a router vulnerability, scan the internet for vulnerable devices at scale, and recruit them faster than any single owner would ever notice or respond. A 9.8 buffer overflow and a command injection bug that requires only "authorized" (not necessarily strongly authenticated) access are both more than sufficient building blocks for that model.
What to check this week
Inventory every D-Link Go-RT-AC750 and DIR-823X device on the network, including in guest networks, branch offices, or any location where consumer-grade hardware may have been deployed informally rather than through a managed procurement process.
Check EoL/EoS status directly against D-Link's published security bulletins before assuming a patch exists — for both of these CVEs, that assumption may be false depending on the specific hardware revision and firmware version in use.
Replace any device confirmed EoL/EoS and internet-facing, since CISA's own requiredAction guidance for both CVEs treats discontinuation as the fallback remediation, not a last resort — that's the intended reading when a patch genuinely isn't coming.
Segment any router that cannot be immediately replaced, restricting its management interface (particularly HNAP and goform endpoints) from any network segment beyond what's strictly necessary.
A closing note on the gap between disclosure and confirmed exploitation
CVE-2022-37055 was originally disclosed in August 2022 and only added to KEV in December 2025 — over three years later. That gap is not evidence the bug was harmless in the interim; it's evidence that confirmed active exploitation takes time to surface and attribute, particularly against devices with no centralized telemetry or update mechanism reporting back to anyone. The population of vulnerable, unpatched Go-RT-AC750 units in December 2025 was very likely a superset of whatever was vulnerable in August 2022, not a subset — EoL hardware doesn't get safer with age.
A final consideration on shadow IT router deployments
Organizations that assume their router fleet consists entirely of enterprise-grade, centrally managed hardware should specifically check for consumer or SOHO-grade D-Link devices that may have entered the environment through remote offices, contractor sites, or ad hoc deployments — exactly the kind of asset that skips normal patch management cycles precisely because it was never formally inventoried.
How Safeguard helps
Safeguard's continuous inventory surfaces network hardware — including consumer and SOHO-grade devices that often evade formal asset tracking — so that EoL/EoS routers running known-exploited firmware are identified and flagged for replacement before they become the botnet foothold an attacker was counting on nobody noticing.