Junglewise Threat Intelligence

CVE-2026-5614: Belkin F9K1015 stack buffer overflow in formSetPassword

CVE-2026-5614 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Belkin F9k1015 Firmware, Belkin F9k1015. Vendors: Belkin.

Executive brief

A security vulnerability exists in the Belkin F9K1015 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker could exploit this flaw to crash the router or potentially take full control of the device. This could lead to a total loss of internet access for the network or allow an attacker to intercept and manipulate network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Belkin F9K1015 firmware version 1.00.10 within the 'webs' server component. The flaw is located in the 'formSetPassword' function in '/goform/formSetPassword', where the 'webpage' parameter is read and subsequently passed to a 'strcpy' call into the 'reboot_msg' buffer without adequate length validation. A remote attacker with low privileges can exploit this by sending a specially crafted POST request containing an oversized 'webpage' argument. Successful exploitation can lead to remote code execution (RCE) or a denial of service (DoS) condition. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Belkin F9K1015 1.00.10

Timeline

  • 2026-04-06: disclosed: Vulnerability disclosed and exploit released to the public.
  • 2026-04-06: advisory: Initial advisory published by VulDB.

References

Related threats