LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 8, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 29, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-37055 to its Known Exploited Vulnerabilities catalog on Dec 8, 2025, with a federal patch deadline of Dec 29, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service…

D-Link routers are affected by a buffer overflow vulnerability tracked as CVE-2022-37055. The flaw carries a high impact on confidentiality, integrity, and availability. Impacted devices may already be at end-of-life or end-of-service status, which limits vendor support options.

How it works

The weakness is classified under CWE-120, a buffer overflow condition. In this class of flaw an attacker supplies input that exceeds the allocated memory buffer because the code does not enforce proper size checks. The resulting memory corruption can alter program flow or data structures. Specific trigger conditions, packet formats, or affected code paths must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor update named in the advisory as the primary step. If the device is end-of-life or end-of-service, discontinue use entirely. For buffer-overflow weaknesses in network appliances, confirm that any remaining devices receive the latest firmware and that unnecessary management services are disabled.

If you can't patch immediately

If your data may have been exposed

Buffer overflow issues in network devices can lead to unauthorized access and data exposure when exploited. Organizations can run a free exposure scan of their email addresses to check known breach data while they complete device inventory and remediation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · Routers
WeaknessCWE-120
Added to CISA KEVDec 8, 2025
Federal patch deadlineDec 29, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities