Command Injection Vulnerability in Belkin F9K1015 Router
CVE-2025-11298
Key Information:
Badges
What is CVE-2025-11298?
A command injection vulnerability exists in the Belkin F9K1015 router due to improper handling of input in the /goform/formSetWanStatic file. By manipulating the 'm_wan_ipaddr' argument, an attacker can potentially execute arbitrary commands on the device from a remote location. This flaw has been publicly disclosed, making devices running the affected firmware version susceptible to exploitation. Despite early notification to the vendor, no response has been received regarding a resolution.
Affected Version(s)
F9K1015 1.00.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved