Junglewise Threat Intelligence

CVE-2026-5611: Belkin F9K1015 stack-based buffer overflow in formCrossBandSwitch

CVE-2026-5611 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Belkin F9k1015 Firmware, Belkin F9k1015. Vendors: Belkin.

Executive brief

A security vulnerability exists in the Belkin F9K1015 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formCrossBandSwitch' function within the '/goform/formCrossBandSwitch' component of Belkin F9K1015 firmware version 1.00.10. The vulnerability is caused by an unsafe 'strcpy' operation where the user-supplied 'webpage' parameter is copied into a fixed-size stack buffer ('reboot_msg') without adequate length validation. A remote attacker with low privileges can exploit this by sending a crafted POST request, leading to a denial of service (system crash) or potential remote code execution. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Belkin F9K1015 1.00.10

Timeline

  • 2026-04-05: disclosed: Initial disclosure via VulDB
  • 2026-04-06: advisory: NVD publication date

References

Related threats