CVE-2026-4167 describes a stack-based buffer overflow vulnerability affecting Belkin F9K1122 firmware version 1.00.33, specifically in the `formReboot` function. This flaw allows a remote attacker with low privileges to manipulate the `webpage` argument, leading to high impacts on confidentiality, integrity, and availability, evidenced by a CVSS score of 8.8 (High). Despite the public disclosure of an exploit, there is no indication of active exploitation (KEV: No) and very low community attention or media coverage. The vendor was unresponsive to early disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Belkin | F9K1122 | 1.00.33CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.