CVE-2025-7083
PoC ×2moderateOS Command Injection in Belkin F9K1122 Router Firmware
CVE-2025-7083 is a command injection flaw (CWE-77/CWE-78) in the 'mp' function of the /goform/mp endpoint of the 'webs' component in Belkin F9K1122 router firmware 1.00.33. It is triggered remotely by manipulating the 'command' argument passed to that endpoint, allowing an attacker to execute operating-system commands on the router; the CVSS 4.0 vector (PR:L, low C/I/A impacts, base score 2.1) indicates at least some privileges (likely an authenticated session) are required and the rated impact is limited, although the assigning CNA classified the flaw as critical. Only Belkin F9K1122 devices running firmware 1.00.33 are identified as affected; the vendor was contacted early but did not respond, so no fixed release is confirmed. A public proof-of-concept has been posted on GitHub, the flaw is not in CISA's KEV, and no in-the-wild exploitation is confirmed, but EPSS assigns a 45.9% (99th-percentile) probability of exploitation within 30 days.
What to do: Check the firmware version on any F9K1122 in use (visible on the router's administration/status page); since Belkin has not responded and no patch is confirmed, mitigate by disabling remote/WAN management and restricting access to the router's web interface and the /goform/mp endpoint to trusted LAN clients only. If the device is internet-exposed, inspect it for signs of tampering (unexpected configuration or DNS changes) and consider replacing this legacy router or monitoring for a vendor advisory.
| Belkin F9K1122 (router firmware) | 1.00.33 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component webs. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- belkin
- Products
- f9k1122 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.