Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wlchannel.html or (2) guestpsk parameter to wlguest.html.
Cross-site request forgery (CSRF) vulnerability in utilsystem.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including passwords and remote management ports.
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".