CVE-2025-7090: Belkin F9K1122 webs formConnectionSetting stack-based overflow
A vulnerability, which was classified as critical, has been found in Belkin F9K1122 1.00.33. Affected by this issue is the function formConnectionSetting of the file /goform/formConnectionSetting of the component webs. The manipulation of the argument maxConn/timeOut leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7090?
CVE-2025-7090 is classified as a critical vulnerability.
What components are affected by CVE-2025-7090?
CVE-2025-7090 affects the function formConnectionSetting in the /goform/formConnectionSetting component of Belkin F9K1122.
How do I fix CVE-2025-7090?
To fix CVE-2025-7090, update the firmware of the Belkin F9K1122 to the latest version provided by the manufacturer.
What are the potential impacts of CVE-2025-7090?
CVE-2025-7090 could lead to exploitation that allows attackers to manipulate stack memory resulting in potential denial of service or remote code execution.
Who is affected by CVE-2025-7090?
Users of the Belkin F9K1122 router with firmware version 1.00.33 are affected by CVE-2025-7090.