Belkin F9K1122 Stack-Based Buffer Overflow Vulnerability in WPS Function
Vulnerability
A critical stack-based buffer overflow vulnerability has been identified in the Belkin F9K1122 router running firmware version 1.00.33. This vulnerability resides in the WPS function of the web interface, specifically within the '/goform/formWpsStart' endpoint. The issue arises because the 'pinCode' argument can be manipulated, allowing remote attackers to overflow the stack and potentially execute arbitrary code. The vulnerability has been publicly disclosed, and an exploit is available.
Impact
Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the affected device.
Reproduction
To reproduce this vulnerability, send a request to the '/goform/formWpsStart' endpoint with a crafted 'pinCode' argument that exceeds the expected length. This will cause a stack-based buffer overflow, which can be exploited to execute arbitrary code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
