CVE-2014-1635 describes a critical buffer overflow vulnerability in the login.cgi component of MiniHttpd, specifically affecting Belkin N750 Routers with firmware older than F9K1103_WW_1.10.17m. This flaw allows unauthenticated remote attackers to execute arbitrary code on the device by sending a crafted, excessively long string to the "jump" parameter. With a CVSS score of 10.0, this vulnerability is highly severe, indicating complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including a Metasploit module and an ExploitDB entry, and it has garnered significant community discussion and media coverage, although it is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10.16nCPE matchmatch criteria | cpe:2.3:o:belkin:n750_wireless_router_firmware:*:*:*:*:*:*:*:* | ||
f9k1103CPE matchmatch criteria | cpe:2.3:h:belkin:n750_wireless_router:f9k1103:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.