← Back

Belkin

belkin

89 CVEs • 55 products

Products (55)

Click to collapse
Toggle
F5d7230 4
f5d7230-4
N750 Firmware
n750_firmware
N300 Firmware
n300_firmware
N300
n300
N900 Firmware
n900_firmware
N900
n900
F5d6130 Wnap
f5d6130_wnap
F5d7232 4
f5d7232-4
F5d7231 4
f5d7231-4
F5d9230 4
f5d9230-4
F5d7632 4
f5d7632-4
F5d8236 4
f5d8236-4
N150 F9k1009
n150_f9k1009
F5d8236 4 V2
f5d8236-4_v2
N750
n750
Wemo Switch
wemo_switch
Linksys E4200
linksys_e4200
F7c063
f7c063
F9k1122
f9k1122
F9k1015
f9k1015

CVEs (89)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Belkin
2N300
N300 Firmware
May 6, 2026
Sep 29, 2014
N/A· v4
N/A· v3
8.3 HIGH· v2
The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.
1Belkin
2N300
N300 Firmware
May 6, 2026
Sep 29, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.
1Belkin
2N900
N900 Firmware
May 6, 2026
Sep 29, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including p...Show more
Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including passwords and remote management ports.Show less
1Belkin
1F5d8236 4 V2
May 6, 2026
Sep 29, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management int...Show more
Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary ports via the remote_mgmt_enabled and remote_mgmt_port parameters.Show less
1Belkin
2N150 F9k1009
N150 F9k1009 Firmware
May 6, 2026
Jun 19, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage paramet...Show more
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.Show less
1Belkin
1Wemo Home Automation Firmware
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware updates and execute arbitrary code via crafted signed data.
1Belkin
1Wemo Home Automation Firmware
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary X.509 certificate.
1Belkin
1Wemo Home Automation Firmware
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.
1Belkin
1Wemo Home Automation Firmware
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access...Show more
The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.Show less
1Belkin
1Wemo Home Automation Firmware
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity re...Show more
The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Belkin
1N300
Apr 29, 2026
Jan 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vec...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vectors.Show less
1Belkin
1N900
Apr 29, 2026
Jan 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_gues...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.Show less
1Belkin
1F5d8236 4
Apr 29, 2026
Jan 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Belkin Model F5D8236-4 v2 router allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Belkin
1N900 Wireless Router
Apr 29, 2026
Dec 31, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC address, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading b...Show more
The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC address, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading broadcast packets, a different vulnerability than CVE-2012-4366.Show less
1Belkin
4N150 Wireless Router
N300 Wireless RouterN450 Wireless Router+1 more
Apr 29, 2026
Nov 20, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a predictable default WPA2-PSK passphrase based on eight digits of the WAN MAC address, whi...Show more
Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a predictable default WPA2-PSK passphrase based on eight digits of the WAN MAC address, which allows remote attackers to access the network by sniffing the beacon frames.Show less
1Belkin
2F5d7632 4
Wireless G Router
Apr 23, 2026
Aug 28, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statuspro...Show more
The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/. NOTE: the setup_dns.exe vector is already covered by CVE-2008-1244.Show less
1Belkin
1F5d7230 4
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connecti...Show more
cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header.Show less
1Belkin
1F5d7230 4
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via th...Show more
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.Show less
1Belkin
1F5d7230 4
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP addre...Show more
The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user, a different vulnerability than CVE-2005-3802.Show less
1Belkin
1F5d9230 4
Apr 23, 2026
Jan 23, 2008
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.