CVE-2026-5042
A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch of the file /goform/formCrossBandSwitch of the component Parameter Handler. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- HIGH
- CVSS base score
- 9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.67%
- CWE
- CWE-121, CWE-119
- Published
- 2026-03-29
- Last modified
- 2026-03-30
Affected products
- Belkin F9K1122
Weakness type
Related vulnerabilities
- CVE-2026-86093 — IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions
- CVE-2026-15419 — CP210x Driver Memory Corruption results in Arbitrary Code Execution
- CVE-2026-88047 — Tesseract: ReadNormProtos stack buffer overflow
- CVE-2026-42805 — A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C...
- CVE-2026-42804 — A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360...
- CVE-2026-88289 — GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers
- CVE-2026-88287 — GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service
- CVE-2026-88284 — GV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of Service