Two high-severity vulnerabilities, CVE-2026-5043 and CVE-2026-5044, were disclosed in the Belkin F9K1122 router running firmware 1.00.33, both enabling remote stack-based buffer overflows through manipulation of the webpage argument. The flaws affect separate handlers: formSetPassword at /goform/formSetPassword and formSetSystemSettings at /goform/formSetSystemSettings, exposing multiple attack paths in the device's web management interface.
Both CVEs are classified under CWE-119 and CWE-121, and published scoring indicates high impact to confidentiality, integrity, and availability. Public exploit information is available for both issues, and the disclosures warn that exploitation may already be occurring in the wild. The reports also state that the vendor was contacted before publication but did not respond, leaving affected Belkin F9K1122 devices potentially exposed without a confirmed vendor remediation path.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability records state that the vendor was reportedly contacted prior to public disclosure. No response from Belkin was reported in the disclosures.
Two remotely exploitable stack-based buffer overflow vulnerabilities affecting Belkin F9K1122 firmware 1.00.33 were publicly disclosed. The flaws impact the formSetPassword and formSetSystemSettings functions via manipulation of the webpage argument, and public exploit information was noted as available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.