Two Belkin router models, F9K1122 firmware 1.00.33 and F9K1015 firmware 1.00.10, were disclosed with remotely exploitable stack-based buffer overflow vulnerabilities in the formWISP5G function exposed through the /goform/formWISP5G endpoint. In both cases, an attacker can manipulate the webpage argument to trigger memory corruption, creating a path to compromise confidentiality, integrity, and availability on affected devices.
The flaws were assigned CVE-2026-4566 and CVE-2026-5610, and both are mapped to CWE-119 and CWE-121. Public exploit availability was noted for each issue, increasing the immediate risk to internet-exposed or unpatched routers. The disclosures also state that the vendor was contacted before publication but did not respond, leaving defenders to identify affected Belkin devices and prioritize mitigation or replacement.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A second CVE entry documented a remotely exploitable stack-based buffer overflow in the formWISP5G function of the /goform/formWISP5G endpoint on Belkin F9K1015 version 1.00.10. The report said the issue was received by cna@vuldb.com on April 6, 2026, that a public exploit had been disclosed, and that the vendor did not respond before publication.
A CVE entry was recorded for a remotely exploitable stack-based buffer overflow in the formWISP5G function of the /goform/formWISP5G endpoint on Belkin F9K1122 firmware 1.00.33. The disclosure noted that a public exploit was available and that the vendor had been contacted earlier but did not respond.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.