---
id: CVE-2025-11295
title: A flaw has been found in Belkin F9K1015 1.00.10
summary: >-
  A flaw has been found in Belkin F9K1015 1.00.10. This affects an unknown part
  of the file /goform/formPPPoESetup. This manipulation of the argument
  pppUserName causes buffer overflow. Remote exploitation of the attack is
  possible. The ex…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: belkin
product: f9k1015_firmware
affected:
  - f9k1015_firmware = 1.00.10
published: '2025-10-05'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11295'
references:
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formPPPoESetup.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formPPPoESetup.md#poc
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327176'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327176'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.661299'
    label: cna@vuldb.com
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formPPPoESetup.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formPPPoESetup.md#poc
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.01087
epssPercentile: 0.64291
ingestedAt: '2026-10-09T12:53:28.687Z'
---

## Overview

A flaw has been found in Belkin F9K1015 1.00.10. This affects an unknown part of the file /goform/formPPPoESetup. This manipulation of the argument pppUserName causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `f9k1015_firmware = 1.00.10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
