Executive brief
A security vulnerability exists in the Belkin F9K1015 wireless router, a device used to provide internet connectivity in home and small office environments. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet access or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow exists in the 'formSetSystemSettings' function within the '/goform/formSetSystemSettings' endpoint of the Belkin F9K1015 firmware version 1.00.10. The vulnerability is caused by an unsafe 'strcpy' operation where the user-provided 'webpage' parameter is copied into a fixed-size stack buffer ('reboot_msg') without adequate length validation. A remote attacker with low privileges can exploit this by sending a POST request with an oversized 'webpage' argument. Successful exploitation can lead to a crash of the 'webs' service (Denial of Service) or potentially remote code execution (RCE). A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Belkin F9K1015 1.00.10
Timeline
- 2026-04-06: disclosed: Public disclosure of the vulnerability and PoC.
- 2026-04-06: advisory: NVD and VulDB published the advisory.