Vulnerability record · CVE-2025-7083 · published 6 July 2025
CVE-2025-7083: Belkin F9K1122 webs component OS command injection via mp
Belkin · F9k1122 Firmware
Belkin F9K1122 firmware 1.00.33 contains an OS command injection flaw in the mp function of /goform/mp, where the command argument is passed to a shell without sanitization. The record is thin on technical detail beyond the vulnerable file and argument, but the flaw is remotely reachable and a public exploit exists. The vendor was contacted and did not respond, so no fix is confirmed.
Description
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component webs. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityRemote OS command injection with a public exploit and very high EPSS outweighs the low CVSS 4.0 score, though the required low privileges temper severity.
What it is
Belkin F9K1122 firmware 1.00.33 contains an OS command injection flaw in the mp function of /goform/mp, where the command argument is passed to a shell without sanitization. The record is thin on technical detail beyond the vulnerable file and argument, but the flaw is remotely reachable and a public exploit exists. The vendor was contacted and did not respond, so no fix is confirmed.
Impact
An attacker who can reach the endpoint can execute arbitrary OS commands on the device, gaining control of the router and any data or traffic it handles. The CVSS 4.0 score of 2.1 (LOW) conflicts with the description's critical classification and the command injection impact, so treat the score with caution.
Attack surface
The vector is network-reachable (AV:N) with low attack complexity and no user interaction, but requires low privileges (PR:L), meaning some form of access or authentication to the device interface is needed. The vulnerable path is /goform/mp in the webs component, reached over the network.
Exploitation
A public exploit is referenced in the GitHub advisory and the record states it may be used; EPSS is 0.45869 (98.7th percentile), indicating elevated likelihood, but the CVE is not in CISA KEV and no ransomware use is documented.
What to do
- Apply a firmware update from Belkin if one becomes available; the vendor did not respond to the disclosure, so confirm support status directly.
- If no patch exists, restrict access to the router management interface to trusted networks and disable remote administration.
- Segment IoT and router devices away from sensitive internal networks to limit lateral movement after compromise.
- Monitor vendor advisories and consider replacing end-of-support hardware that will not receive fixes.
Detection
- Inspect HTTP requests to /goform/mp for shell metacharacters or unexpected command strings in the command parameter.
- Monitor router and upstream logs for outbound connections or process execution consistent with injected commands.
- Alert on anomalous traffic from the device to external hosts, which may indicate command-and-control or exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Belkin/vuln_3/3.md | ExploitThird Party Advisory |
| https://github.com/wudipjq/my_vuln/blob/main/Belkin/vuln_3/3.md#poc | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.314997 | Permissions Required |
| https://vuldb.com/?id.314997 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.603673 | Third Party AdvisoryVDB Entry |
| https://github.com/wudipjq/my_vuln/blob/main/Belkin/vuln_3/3.md | ExploitThird Party Advisory |
Track CVE-2025-7083 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-7083), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.