Junglewise Threat Intelligence

CVE-2026-5629: Belkin F9K1015 stack-based buffer overflow in formSetFirewall

CVE-2026-5629 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Belkin F9k1015 Firmware, Belkin F9k1015. Vendors: Belkin.

Executive brief

A security vulnerability exists in the Belkin F9K1015 wireless router, a device used to provide internet connectivity and network security for homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet access or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formSetFirewall' function within the '/goform/formSetFirewall' endpoint of Belkin F9K1015 firmware version 1.00.10. The root cause is an unsafe 'strcpy' operation where a user-provided parameter, 'webpage', is copied into a fixed-size stack buffer ('last_url') without length validation. An attacker with network access and low-level privileges can trigger this overflow by sending a POST request with an excessively long string in the 'webpage' argument. Successful exploitation can lead to a denial of service (DoS) or remote code execution (RCE). As of the advisory date, the vendor has not responded to disclosure attempts, and a public exploit (PoC) is available.

Affected products

  • Belkin F9K1015 1.00.10

Timeline

  • 2026-04-06: disclosed: Vulnerability disclosed and public exploit released.
  • 2026-04-06: advisory: NVD published the CVE entry.

References

Related threats