Description
A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-06
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a stack-based buffer overflow in the formSetPassword function found in the Belkin F9K1015 firmware. An attacker can send a crafted request that overflows the buffer by manipulating the 'webpage' argument sent to the /goform/formSetPassword endpoint. Because the overflow occurs on the stack, a successful exploitation allows an attacker to execute arbitrary code with the privileges of the device, giving full control over the system. This flaw falls under CWE-119 (Improper Restriction of Operations within the Bounds of a Buffer) and CWE-121 (Stack-Based Buffer Overflow).

Affected Systems

The affected device is the Belkin F9K1015, running firmware version 1.00.10. Only the firmware version 1.00.10 is documented as vulnerable; earlier or newer versions are not listed as affected in the available data.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. No EPSS score is available, but the public release of an exploit demonstrates that attackers already have access to working payloads. The flaw is not listed in the CISA KEV catalog yet. Exploitation requires sending HTTP requests to the device's management interface, which is accessible remotely, meaning an attacker can target the device from the internet if the network permits. Given the high severity and the availability of a public exploit, the risk to exposed devices is substantial.

Generated by OpenCVE AI on April 6, 2026 at 06:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Belkin F9K1015 firmware to a version in which the formSetPassword function has been fixed
  • If a firmware update is not yet available, block or disable external network access to the device's HTTP management interface to prevent remote exploitation
  • Regularly monitor device logs for failed or unusual access attempts to the /goform/formSetPassword endpoint
  • Contact Belkin again to request an official patch and follow up regularly

Generated by OpenCVE AI on April 6, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Belkin f9k1015
Vendors & Products Belkin f9k1015

Mon, 06 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Belkin F9K1015 formSetPassword stack-based overflow
First Time appeared Belkin
Belkin f9k1015 Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:belkin:f9k1015_firmware:*:*:*:*:*:*:*:*
Vendors & Products Belkin
Belkin f9k1015 Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Belkin F9k1015 F9k1015 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-06T18:25:07.762Z

Reserved: 2026-04-05T15:29:57.819Z

Link: CVE-2026-5614

cve-icon Vulnrichment

Updated: 2026-04-06T18:25:03.275Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-06T04:16:09.967

Modified: 2026-04-07T13:20:35.010

Link: CVE-2026-5614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:47:32Z

Weaknesses