Exploited Known exploited (KEV) CVE-2022-37055

A buffer overflow in D-Link routers (CVE-2022-37055) — the record notes the products may be end-of-life and tells users to discontinue use

D-Link Routers Added to KEV Dec 8, 2025 Federal remediation due 2025-12-29

D-Link routers contain a buffer overflow vulnerability with high impact on confidentiality, integrity and availability. The catalog notes that the impacted products could be end-of-life (EoL) or end-of-service (EoS) and states that users should discontinue product utilization.

Key facts

  • CVE IDCVE-2022-37055
  • Affected (vendor / product)D-Link Routers
  • CWECWE-120
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2025-12-29 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is D-Link Routers; CWE-120, buffer copy without checking size of input.
  • The catalog cites high impact on confidentiality, integrity and availability alike.
  • It notes the impacted products could be end-of-life or end-of-service and states that users should discontinue product utilization.
  • Added to KEV 2025-12-08 with a due date of 2025-12-29.
  • Of the 1,685 records this site holds as of 2026-08-28, 702 (41.7 percent) contain discontinue-use wording, but most are the standard formula conditioned on mitigations being unavailable.
  • Where the supply of updates has ended, discontinuing use is the only response left.

1When fixing is not among the options

Responding to a vulnerability normally starts with applying an update. This record, however, notes that the supply of updates may itself have ended. End-of-life means sales and development have stopped; end-of-service means fixes and support enquiries are no longer handled. Under either, no correction arrives for a newly discovered fault. The record tells users to discontinue use because nothing else remains available to them.

2Equipment that stays in place

A router is the archetype of a device nobody touches while it keeps working. It does not raise update prompts the way a computer or a phone does, and models from years back carrying live traffic are unremarkable. From the perspective of an attacker it is a device permanently facing the internet, receiving no fixes, and owned by someone not thinking about updates.

That the record cites high impact on confidentiality, integrity and availability alike follows partly from a router being the entrance to the network itself.

3Discontinue-use wording appears on four records in ten

Of the 1,685 KEV records this site holds as of 2026-08-28, 70241.7 percent — include discontinue-use wording in the required action. Most of those, though, are the standard formula conditioned on mitigations being unavailable. What differs here is that the statement appears inside the description of the vulnerability itself: users should discontinue product utilization.

It is written as the expected conclusion, not as a conditional option. Which specific models are affected is left to the vendor advisory and is not part of the catalog record.

4Fix it, or stop using it

The basic response to a vulnerability is to apply an update. This record, however, notes that the supply of updates may itself have ended. When it has, only one option remains.

Update it and keep using itDiscontinue use
Presupposes the vendor is shipping fixesThe only move when no fix will come
The equipment can stay where it isReplacement costs money and effort
The response closes as a recordIt begins with choosing a replacement
It can happen without the user noticingNothing changes unless the user acts

End of life means sales and development have ended; end of support means fixes and enquiries are no longer answered. Under either, no fix arrives for a newly found fault. A router is the archetype of equipment nobody touches while it works, and from an attacker's view it is a device permanently facing the internet, receiving no fixes, whose owner never thinks about updating it.

Why it matters

Equipment that cannot be fixed by updating falls outside the frame of vulnerability management, because apply-by-the-deadline does not work where no fix exists. Assets on the register end up with a remediation column that can never be filled, so the decision to replace has to be a managed item in its own right.

FAQ

How do EoL and EoS differ?
End-of-life means sales and development have stopped; end-of-service means fixes and support enquiries are no longer handled. Under either, no correction arrives for a new fault.
Why are routers targeted?
They face the internet permanently, are rarely touched once installed, and raise no update prompts. That the record cites impact on confidentiality, integrity and availability alike follows partly from a router being the entrance to the network.
Which models are affected?
That is not part of the catalog record; the specific models are left to the vendor advisory.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#D-Link#Routers#End of service
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.