Description
A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch of the file /goform/formCrossBandSwitch of the component Parameter Handler. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-03-29
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow exists in the formCrossBandSwitch function of Belkin F9K1122’s web interface. By manipulating the webpage argument, an attacker can overwrite the stack, potentially executing arbitrary code on the router. The flaw is exploitable remotely through the device’s HTTP management interface, giving attackers a full compromise of the device.

Affected Systems

The vulnerability affects Belkin F9K1122 routers running firmware version 1.00.33. No other firmware releases are listed as affected in the data.

Risk and Exploitability

The CVSS base score of 8.7 classifies the issue as high severity, and the EPSS score indicates that the likelihood of public exploitation is currently low (<1 %). However, an exploit has already been released, and because the flaw is triggered remotely over the web interface, any exposed router remains at risk unless mitigated. The vulnerability is not yet catalogued in the CISA KEV database.

Generated by OpenCVE AI on March 30, 2026 at 20:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the firmware version on the router; if it is 1.00.33, upgrade to a patched version as soon as it becomes available.
  • If no update exists, block remote access to the router’s web interface using firewall rules or VPN, limiting administration to the local network.
  • If the device supports it, disable or lock down the formCrossBandSwitch feature to prevent exploitation.
  • Continuously monitor network traffic and router logs for suspicious activity related to the exposed web interface.

Generated by OpenCVE AI on March 30, 2026 at 20:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 30 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CPEs cpe:2.3:h:belkin:f9k1122:-:*:*:*:*:*:*:*
cpe:2.3:o:belkin:f9k1122_firmware:1.00.33:*:*:*:*:*:*:*

Mon, 30 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Belkin f9k1122
Vendors & Products Belkin f9k1122

Sun, 29 Mar 2026 10:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch of the file /goform/formCrossBandSwitch of the component Parameter Handler. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Belkin F9K1122 Parameter formCrossBandSwitch stack-based overflow
First Time appeared Belkin
Belkin f9k1122 Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:belkin:f9k1122_firmware:*:*:*:*:*:*:*:*
Vendors & Products Belkin
Belkin f9k1122 Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Belkin F9k1122 F9k1122 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-30T14:52:35.882Z

Reserved: 2026-03-27T16:35:43.170Z

Link: CVE-2026-5042

cve-icon Vulnrichment

Updated: 2026-03-30T13:14:05.119Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-29T11:16:34.867

Modified: 2026-03-30T18:58:01.433

Link: CVE-2026-5042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T20:56:51Z

Weaknesses