Impact
A stack‑based buffer overflow exists in the formCrossBandSwitch handler of Belkin F9K1015 firmware 1.00.10. Manipulating the "webpage" argument sent to the /goform/formCrossBandSwitch endpoint causes the overflow, which can corrupt the stack and enable arbitrary code execution or a denial of service. The vulnerability is reportable as a remote exploitation vector, meaning an attacker only needs network reachability to the device to trigger it, and public exploits have already been released.
Affected Systems
Belkin F9K1015 devices running firmware 1.00.10 are affected. The flaw resides in the web interface, specifically the formCrossBandSwitch functionality, and is limited to this firmware release. No other firmware versions or models are listed as impacted.
Risk and Exploitability
The CVSS base score of 8.7 assigns a high severity, reflecting significant confidentiality, integrity, and availability damage potential. The publicly available exploit and lack of vendor response reduce the time window for remediation. Although there is no EPSS score or KEV listing, the remote nature of the attack coupled with the stack overflow weakness (CWE‑119 and CWE‑121) makes this vulnerability likely to be actively exploited by skilled adversaries.
OpenCVE Enrichment