Junglewise Threat Intelligence

CVE-2026-5613: Belkin F9K1015 stack-based buffer overflow in formReboot

CVE-2026-5613 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Belkin F9k1015 Firmware, Belkin F9k1015. Vendors: Belkin.

Executive brief

A security vulnerability exists in the Belkin F9K1015 wireless router that could allow an attacker to take control of the device. By sending a specially crafted request to the router's reboot function, an attacker can cause the system to crash or execute unauthorized commands. This could lead to a total loss of device availability, interception of network traffic, or unauthorized access to the home or office network.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formReboot' function within the '/goform/formReboot' component of Belkin F9K1015 firmware version 1.00.10. The issue stems from the unsafe use of the 'strcpy' function when processing the user-supplied 'webpage' argument, which lacks proper length validation before being copied into the 'ok_msg' buffer. A remote attacker with low privileges can exploit this by sending a malicious POST request containing an oversized string, leading to memory corruption. This can result in a denial of service (system crash) or potentially remote code execution (RCE). A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Belkin F9K1015 1.00.10

Timeline

  • 2026-04-05: disclosed: Vulnerability first reported by VulDB
  • 2026-04-06: advisory: NVD publication date

References

Related threats