---
id: CVE-2026-5614
title: A security flaw has been discovered in Belkin F9K1015 1.00.10
summary: >-
  A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the
  function formSetPassword of the file /goform/formSetPassword. The manipulation
  of the argument webpage results in stack-based buffer overflow. The attack may
  …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-121
vendor: belkin
product: f9k1015_firmware
affected:
  - f9k1015_firmware = 1.00.10
published: '2026-04-06'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5614'
references:
  - url: >-
      https://github.com/Litengzheng/vuldb_new/blob/main/Belkin%20F9K1015/vul_11/README.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/785554'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355405'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355405/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.01456
epssPercentile: 0.72329
ingestedAt: '2026-07-24T09:23:51.781Z'
---

## Overview

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `f9k1015_firmware = 1.00.10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
