CVE-2026-5043Disclosure(belkin / f9k1122)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the file /goform/formSetPassword of the component Parameter Handler. This manipulation of the argument webpage causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f9k1122
  • f9k1122_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
f9k1122f9k1122_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-29: 3PoC Mentioned / Linked · 2026-03-29: 1Technical Details · 2026-03-29: 203-29
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5043 A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the file /goform/formSetPassword of the component Para… https://www.cve.org/CVERecord?id=CVE-2026-5043

    Post summary

    A new vulnerability (CVE-2026-5043) was identified in Belkin F9K1122 firmware, affecting the formSetPassword function, with no details on exploitation, patches, or mitigations provided.

    0001090
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5043 - High A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the file /goform/formSetPassword of the component Parameter Handler. This mani... https://www.thehackerwire.com/vulnerability/CVE-2026-5043/ https://t.co/QCnAUp2rE8

    Post summary

    The tweet announces a high‑severity vulnerability in the Belkin F9K1122 router, describing the affected function and component, but provides no PoC, exploit, active exploitation, or patch information.

    0000033
    163 followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-5043: HIGH] Vulnerability in Belkin F9K1122 could lead to remote stack-based buffer overflow attack via formSetPassword function, with exploit now public. No vendor response to disclosure.#cve,CVE-2026-5043,#cybersecurity https://cvefind.com/CVE-2026-5043

    Post summary

    Belkin's F9K1122 router is vulnerable to a remote stack‑based buffer overflow via the formSetPassword API; an exploit has become public, but no vendor patch or active exploitation reports are mentioned.

    0000044
    617 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWbelkinf9k1122---
OSbelkinf9k1122_firmware1.00.33--

Explore more