Belkin F9K1122 Stack-Based Buffer Overflow Vulnerability in WPS Setup Function
Vulnerability
A critical stack-based buffer overflow vulnerability has been identified in the Belkin F9K1122 router running firmware version 1.00.33. This vulnerability resides in the WPS setup function, specifically within the file '/goform/formWlanSetupWPS'. The issue arises when the 'wps_enrolee_pin' and 'webpage' arguments are manipulated, allowing remote attackers to overflow the stack and potentially execute arbitrary code. The vulnerability has been publicly disclosed, and an exploit is available.
Impact
Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the affected device.
Reproduction
To reproduce this vulnerability, send a request to the '/goform/formWlanSetupWPS' endpoint with overly long data in the 'wps_enrolee_pin' and 'webpage' arguments. This will cause a stack overflow, which can be exploited to execute arbitrary code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
