Belkin F9K1122 Stack-Based Buffer Overflow Vulnerability in WPS Setup Function

Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in the Belkin F9K1122 router running firmware version 1.00.33. This vulnerability resides in the WPS setup function, specifically within the file '/goform/formWlanSetupWPS'. The issue arises when the 'wps_enrolee_pin' and 'webpage' arguments are manipulated, allowing remote attackers to overflow the stack and potentially execute arbitrary code. The vulnerability has been publicly disclosed, and an exploit is available.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution on the affected device.

Reproduction

To reproduce this vulnerability, send a request to the '/goform/formWlanSetupWPS' endpoint with overly long data in the 'wps_enrolee_pin' and 'webpage' arguments. This will cause a stack overflow, which can be exploited to execute arbitrary code.

Added: Jul 6, 2025, 8:17 PM
Updated: Jul 6, 2025, 8:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.