Executive brief
A security vulnerability has been identified in the Belkin F9K1015 wireless router. This device is used to provide internet connectivity and manage local network traffic for home and small office environments. An attacker could exploit this flaw to crash the router or potentially take full control of the device, which could lead to the interception of network traffic or unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Belkin F9K1015 router firmware version 1.00.10. The flaw is located within the 'formWISP5G' function in the '/goform/formWISP5G' component. The vulnerability is triggered when the 'webpage' parameter is processed; the application uses the 'strcpy' function to copy user-supplied data into a stack buffer without performing adequate length validation. A remote attacker with low privileges can exploit this by sending a specially crafted POST request containing an oversized 'webpage' argument. Successful exploitation can lead to arbitrary code execution or a denial-of-service (DoS) condition. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- Belkin F9K1015 1.00.10
Timeline
- 2026-04-06: disclosed: Public disclosure of the exploit and vulnerability details.
- 2026-04-06: advisory