Impact
A stack-based buffer overflow occurs in the formReboot function when the webpage argument is manipulated. This flaw allows an attacker to corrupt the device’s stack, potentially leading to the execution of arbitrary code. The vulnerability can be triggered from a remote location because the vulnerable endpoint is accessible over the network. The presence of a publicly available exploit increases the risk that attackers could successfully target vulnerable devices.
Affected Systems
The flaw exists in Belkin’s F9K1015 home networking device with firmware version 1.00.10. Only this specific firmware build is known to be affected, as indicated by the vendor’s product identification and the referenced CPE string.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the lack of an EPSS value does not diminish the seriousness of potential exploitation. The vulnerability is not listed in the CISA KEV catalog, but because the attack vector is remote and exploits are publicly available, the likelihood that attackers will target affected devices is significant. Due to the vendor’s lack of response, there is no official patch currently available, further increasing the security gap.
OpenCVE Enrichment