Belkin's vulnerability footprint centers on consumer and small-business networking devices, particularly wireless routers and related firmware, which represent a broadly accessible attack surface in home and office environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency to acquire public exploit code; the combination positions these devices as targets for remote compromise and botnet recruitment. The exposure recurs across product lines such as the F9K routers and their firmware images through weakness classes including buffer overflows, improper memory-boundary handling, and OS command injection—flaws endemic to embedded networking firmware where memory constraints and legacy protocols intersect. Defenders should inventory affected router models, prioritize patching or replacement of long-lived devices, and restrict management interfaces from untrusted networks; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Belkin over time
Signals from CVEs in this vendor scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-1635HIGH Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the | Nov 12, 2014 | 10.0 | 84 | NO | YES |
CVE-2019-12780CRITICAL The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/b | Jun 10, 2019 | 9.8 | 80 | NO | YES |
CVE-2014-2962HIGH Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files vi | Jun 19, 2014 | 7.8 | 70 | NO | YES |
CVE-2018-1143CRITICAL A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi. | Apr 19, 2018 | 9.8 | 62 | NO | NO |
CVE-2025-7083HIGH A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component webs. The manipulation | Jul 6, 2025 | 8.8 | 45 | NO | NO |
CVE-2018-1145CRITICAL A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi. | Apr 19, 2018 | 9.8 | 41 | NO | NO |
CVE-2013-2748CRITICAL Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. | Jan 28, 2020 | 9.8 | 40 | NO | YES |
CVE-2018-1146HIGH A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to set.cgi. When enabled the telnet session requ | Apr 19, 2018 | 7.5 | 38 | NO | NO |
CVE-2013-2679MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the | Feb 18, 2020 | 6.1 | 36 | NO | YES |
CVE-2008-7115HIGH The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileg | Aug 28, 2009 | 10.0 | 36 | NO | YES |
Signals from CVEs in this vendor scope (90 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Belkin.
Media articles that mention a CVE ID that affects a product developed by Belkin — matched by CVE ID, not by vendor name.