CVE-2025-7082: Belkin F9K1122 webs formBSSetSitesurvey os command injection
A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function formBSSetSitesurvey of the file /goform/formBSSetSitesurvey of the component webs. The manipulation of the argument wanipaddr/wannetmask/wangateway/wlssid is directly passed by the attacker/so we can control the wanipaddr/wannetmask/wangateway/wlssid leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7082?
CVE-2025-7082 is classified as critical due to its potential impact on affected systems.
How do I fix CVE-2025-7082?
To fix CVE-2025-7082, you should update the Belkin F9K1122 router firmware to the latest version provided by the manufacturer.
What components are affected by CVE-2025-7082?
CVE-2025-7082 affects the web component of the Belkin F9K1122 router, specifically the formBSSetSitesurvey function.
What is the impact of exploiting CVE-2025-7082?
Exploiting CVE-2025-7082 could allow unauthorized access and manipulation of critical network settings.
Is there any workaround for CVE-2025-7082?
Currently, the recommended action is to apply the firmware update, as there are no official workarounds provided.