Junglewise Threat Intelligence

CVE-2026-5608: Belkin F9K1122 stack-based buffer overflow in formWlanSetup

CVE-2026-5608 · Severity: high · CVSS 8.8 · Published 2026-04-06

Vendors: Belkin.

Executive brief

A security vulnerability has been identified in the Belkin F9K1122 wireless router. This flaw exists in the device's web-based setup interface, which is used to manage Wi-Fi settings. If exploited, a remote attacker could cause the router to crash or potentially take full control of the device, leading to a complete loss of internet connectivity and the potential compromise of network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Belkin F9K1122 router firmware version 1.00.33. The flaw is located within the 'formWlanSetup' function in the '/goform/formWlanSetup' file. The vulnerability is triggered when the 'webpage' argument is processed; specifically, the 'p_reboot_msg' variable is passed to a 'strcpy' function call without adequate length validation, overflowing the 'reboot_msg' buffer. An attacker with network access can exploit this by sending a specially crafted POST request. Successful exploitation can lead to a denial of service (DoS) or remote code execution (RCE). As of the advisory date, the vendor has not responded to disclosure attempts, and a public exploit is available.

Affected products

  • Belkin F9K1122 1.00.33

Timeline

  • 2026-04-05: disclosed: Vulnerability first reported to VulDB
  • 2026-04-06: advisory: NVD publication date

References