Belkin F9K1122 OS Command Injection Vulnerability

Vulnerability

A critical OS command injection vulnerability has been identified in the Belkin F9K1122 router running firmware version 1.00.33. The issue arises in the 'formSetWanStatic' function within the '/goform/formSetWanStatic' file, where user-supplied arguments for IP address, netmask, gateway, and DNS servers are not properly sanitized before being executed as OS commands. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.

Reproduction

To reproduce this vulnerability, send a crafted request to the '/goform/formSetWanStatic' endpoint, including malicious payloads in the 'm_wan_ipaddr', 'm_wan_netmask', 'm_wan_gateway', 'm_wan_staticdns1', and 'm_wan_staticdns2' fields. The lack of input validation will result in the execution of the injected commands on the router's operating system.

Added: Jul 6, 2025, 2:18 PM
Updated: Jul 6, 2025, 2:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.2
threat
6.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.