PT-2025-40808 · Belkin · Belkin F9K1015

Panda_0X1

+1

·

Published

2025-09-23

·

Updated

2026-02-24

·

CVE-2025-11292

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Belkin F9K1015 version 1.00.10
Description A flaw exists in Belkin F9K1015 version 1.00.10 that allows for command injection. This occurs through manipulation of the wan ipaddr argument within an unknown function of the /goform/formBSSetSitesurvey file. The attack can be initiated remotely, and details about the exploit are publicly available. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-12609
CVE-2025-11292

Affected Products

Belkin F9K1015