Executive brief
A security vulnerability has been identified in the Belkin F9K1122 wireless router. This flaw exists in the device's web-based setup interface, which is used to manage Wi-Fi settings. If exploited, a remote attacker could cause the router to crash or potentially take full control of the device, leading to a complete loss of internet connectivity and the potential compromise of network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Belkin F9K1122 router firmware version 1.00.33. The flaw is located within the 'formWlanSetup' function in the '/goform/formWlanSetup' file. The vulnerability is triggered when the 'webpage' argument is processed; specifically, the 'p_reboot_msg' variable is passed to a 'strcpy' function call without adequate length validation, overflowing the 'reboot_msg' buffer. An attacker with network access can exploit this by sending a specially crafted POST request. Successful exploitation can lead to a denial of service (DoS) or remote code execution (RCE). As of the advisory date, the vendor has not responded to disclosure attempts, and a public exploit is available.
Affected products
- Belkin F9K1122 1.00.33
Timeline
- 2026-04-05: disclosed: Vulnerability first reported to VulDB
- 2026-04-06: advisory: NVD publication date