CVE-2026-5613 affects Belkin F9K1015 wireless router version 1.00.10 and involves a stack-based buffer overflow vulnerability in the formReboot function accessible via the /goform/formReboot endpoint. An attacker can manipulate the webpage argument to trigger the overflow condition, potentially compromising the device. The vulnerability carries a HIGH severity rating (CVSS 8.8) with a network-based attack vector requiring low complexity and authenticated access. A successful exploit could result in high-impact consequences including confidentiality breach, integrity compromise, and complete availability disruption of the affected router. Exploitation status indicates that while public exploit code is available, the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. Community attention remains low, with the EPSS score suggesting minimal likelihood of near-term exploitation compared to other disclosed vulnerabilities. The vendor did not respond to early disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00.10CPE matchmatch criteria | cpe:2.3:o:belkin:f9k1015_firmware:1.00.10:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.