---
id: CVE-2025-11297
title: A vulnerability was found in Belkin F9K1015 1.00.10
summary: >-
  A vulnerability was found in Belkin F9K1015 1.00.10. This issue affects some
  unknown processing of the file /goform/formSetLanguage. Performing a
  manipulation of the argument webpage results in buffer overflow. The attack is
  possible to …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: belkin
product: f9k1015_firmware
affected:
  - f9k1015_firmware = 1.00.10
published: '2025-10-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11297'
references:
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formSetLanguage.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formSetLanguage.md#poc
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327178'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327178'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.661301'
    label: cna@vuldb.com
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formSetLanguage.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/panda666-888/vuls/blob/main/belkin/f9k1015/formSetLanguage.md#poc
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0108
epssPercentile: 0.63818
ingestedAt: '2026-09-30T23:29:32.416Z'
---

## Overview

A vulnerability was found in Belkin F9K1015 1.00.10. This issue affects some unknown processing of the file /goform/formSetLanguage. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `f9k1015_firmware = 1.00.10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
