← Back

Belkin

belkin

89 CVEs • 55 products

Products (55)

Click to collapse
Toggle
F5d7230 4
f5d7230-4
N750 Firmware
n750_firmware
N300 Firmware
n300_firmware
N300
n300
N900 Firmware
n900_firmware
N900
n900
F5d6130 Wnap
f5d6130_wnap
F5d7232 4
f5d7232-4
F5d7231 4
f5d7231-4
F5d9230 4
f5d9230-4
F5d7632 4
f5d7632-4
F5d8236 4
f5d8236-4
N150 F9k1009
n150_f9k1009
F5d8236 4 V2
f5d8236-4_v2
N750
n750
Wemo Switch
wemo_switch
Linksys E4200
linksys_e4200
F7c063
f7c063
F9k1122
f9k1122
F9k1015
f9k1015

CVEs (89)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Belkin
1N300 Firmware
Nov 21, 2024
May 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameter...Show more
In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.Show less
1Belkin
1Linksys Wrt160nl Firmware
Nov 21, 2024
Feb 2, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language...Show more
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs in do_upgrade_post in mini_httpd. NOTE: This vulnerability only affects products that are no longer supported by the maintaineShow less
1Belkin
1Linksys Wrt 160nl Firmware
Nov 21, 2024
Oct 23, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code execution. NOTE: Thi...Show more
Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Belkin
1Linksys E4200 Firmware
Nov 21, 2024
Feb 18, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_siz...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.Show less
1Belkin
1N750 Firmware
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Belkin n750 routers have a buffer overflow.
1Belkin
1N300 Firmware
Nov 21, 2024
Feb 7, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
1Belkin
1Wemo Switch Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
1Belkin
1Wemo Insight Switch Firmware
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Swi...Show more
A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions.Show less
1Belkin
1N900 Firmware
Nov 21, 2024
Dec 26, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
1Belkin
1F5d8236 4 Firmware
Nov 21, 2024
Dec 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
1Belkin
1N900 Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
1Belkin
1Wemo Switch 28b Firmware
Nov 21, 2024
Oct 12, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a St...Show more
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.Show less
1Belkin
1Crock Pot Smart Slow Cooker With Wemo Firmware
Nov 21, 2024
Jun 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to exec...Show more
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.Show less
1Belkin
1Wemo Insight Smart Plug Firmware
Nov 21, 2024
Aug 21, 2018
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet.
1Belkin
1N750 Firmware
Nov 21, 2024
Apr 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to set.cgi. When enabled the telnet session requires no password and provides root acces...Show more
A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to set.cgi. When enabled the telnet session requires no password and provides root access.Show less
1Belkin
1N750 Firmware
Nov 21, 2024
Apr 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.
1Belkin
1N750 Firmware
Nov 21, 2024
Apr 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.
1Belkin
1N750 Firmware
Nov 21, 2024
Apr 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi.
1Belkin
1N300 Dual Band Wi Fi Range Extender Firmware
May 6, 2026
Aug 13, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2...Show more
Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS request; or unspecified parameters in a (5) formWlanMP, (6) formBSSetSitesurvey, (7) formHwSet, or (8) formConnectionSetting request.Show less
1Belkin
2N750 Wireless Router
N750 Wireless Router Firmware
May 6, 2026
Nov 12, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter.