belkin CVE Vulnerabilities & Metrics

Focus on belkin vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About belkin Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with belkin. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total belkin CVEs: 21
Earliest CVE date: 31 Dec 2002, 05:00 UTC
Latest CVE date: 13 Jul 2023, 16:15 UTC

Latest CVE reference: CVE-2023-33768

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical belkin CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 7.07

Max CVSS: 10.0

Critical CVEs (≥9): 15

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 16
7.0-8.9 16
9.0-10.0 15

CVSS Distribution Chart

Top 5 Highest CVSS belkin CVEs

These are the five CVEs with the highest CVSS scores for belkin, sorted by severity first and recency.

All CVEs for belkin

CVE-2023-33768 belkin vulnerability CVSS: 0 13 Jul 2023, 16:15 UTC

Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file.

CVE-2023-27217 belkin vulnerability CVSS: 0 18 May 2023, 03:15 UTC

A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request.

CVE-2022-30105 belkin vulnerability CVSS: 10.0 18 May 2022, 16:15 UTC

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.

CVE-2021-25310 belkin vulnerability CVSS: 9.0 02 Feb 2021, 15:15 UTC

The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs in do_upgrade_post in mini_httpd. NOTE: This vulnerability only affects products that are no longer supported by the maintaine

CVE-2020-26561 belkin vulnerability CVSS: 6.5 23 Oct 2020, 06:15 UTC

Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2013-2679 belkin vulnerability CVSS: 4.3 18 Feb 2020, 17:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.

CVE-2013-7173 belkin vulnerability CVSS: 10.0 13 Feb 2020, 23:15 UTC

Belkin n750 routers have a buffer overflow.

CVE-2013-3091 belkin vulnerability CVSS: 10.0 07 Feb 2020, 19:15 UTC

An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

CVE-2013-2748 belkin vulnerability CVSS: 7.5 28 Jan 2020, 20:15 UTC

Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

CVE-2019-17094 belkin vulnerability CVSS: 7.2 27 Jan 2020, 18:15 UTC

A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain code execution on the device. This issue affects: Belkin WeMo Insight Switch firmware version 2.00.11396 and prior versions.

CVE-2013-3088 belkin vulnerability CVSS: 9.3 26 Dec 2019, 23:15 UTC

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

CVE-2013-3085 belkin vulnerability CVSS: 7.5 26 Dec 2019, 23:15 UTC

An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

CVE-2013-4655 belkin vulnerability CVSS: 7.8 13 Nov 2019, 16:15 UTC

Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.

CVE-2019-17532 belkin vulnerability CVSS: 7.8 12 Oct 2019, 21:15 UTC

An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.

CVE-2019-12780 belkin vulnerability CVSS: 7.5 10 Jun 2019, 16:29 UTC

The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

CVE-2018-6692 belkin vulnerability CVSS: 10.0 21 Aug 2018, 14:29 UTC

Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet.

CVE-2018-1146 belkin vulnerability CVSS: 5.0 19 Apr 2018, 13:29 UTC

A remote unauthenticated user can enable telnet on the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to set.cgi. When enabled the telnet session requires no password and provides root access.

CVE-2018-1145 belkin vulnerability CVSS: 7.5 19 Apr 2018, 13:29 UTC

A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.

CVE-2018-1144 belkin vulnerability CVSS: 10.0 19 Apr 2018, 13:29 UTC

A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.

CVE-2018-1143 belkin vulnerability CVSS: 10.0 19 Apr 2018, 13:29 UTC

A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi.

CVE-2015-5536 belkin vulnerability CVSS: 9.0 13 Aug 2015, 14:59 UTC

Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS request; or unspecified parameters in a (5) formWlanMP, (6) formBSSetSitesurvey, (7) formHwSet, or (8) formConnectionSetting request.

CVE-2014-1635 belkin vulnerability CVSS: 10.0 12 Nov 2014, 16:55 UTC

Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter.

CVE-2013-3092 belkin vulnerability CVSS: 8.3 29 Sep 2014, 22:55 UTC

The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.

CVE-2013-3089 belkin vulnerability CVSS: 6.8 29 Sep 2014, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.

CVE-2013-3086 belkin vulnerability CVSS: 6.8 29 Sep 2014, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including passwords and remote management ports.

CVE-2013-3083 belkin vulnerability CVSS: 6.8 29 Sep 2014, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary ports via the remote_mgmt_enabled and remote_mgmt_port parameters.

CVE-2014-2962 belkin vulnerability CVSS: 7.8 19 Jun 2014, 10:50 UTC

Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

CVE-2013-6952 belkin vulnerability CVSS: 10.0 22 Feb 2014, 21:55 UTC

The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware updates and execute arbitrary code via crafted signed data.

CVE-2013-6951 belkin vulnerability CVSS: 7.1 22 Feb 2014, 21:55 UTC

The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary X.509 certificate.

CVE-2013-6950 belkin vulnerability CVSS: 7.8 22 Feb 2014, 21:55 UTC

The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the-middle attackers to install arbitrary firmware by spoofing a distribution server.

CVE-2013-6949 belkin vulnerability CVSS: 9.3 22 Feb 2014, 21:55 UTC

The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.

CVE-2013-6948 belkin vulnerability CVSS: 7.8 22 Feb 2014, 21:55 UTC

The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVE-2013-3090 belkin vulnerability CVSS: 4.3 30 Jan 2014, 15:06 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vectors.

CVE-2013-3087 belkin vulnerability CVSS: 4.3 30 Jan 2014, 15:06 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.

CVE-2013-3084 belkin vulnerability CVSS: 4.3 30 Jan 2014, 15:06 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Belkin Model F5D8236-4 v2 router allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2012-6371 belkin vulnerability CVSS: 3.3 31 Dec 2012, 20:55 UTC

The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC address, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading broadcast packets, a different vulnerability than CVE-2012-4366.

CVE-2012-4366 belkin vulnerability CVSS: 3.3 20 Nov 2012, 00:55 UTC

Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a predictable default WPA2-PSK passphrase based on eight digits of the WAN MAC address, which allows remote attackers to access the network by sniffing the beacon frames.

CVE-2008-7115 belkin vulnerability CVSS: 10.0 28 Aug 2009, 15:30 UTC

The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/. NOTE: the setup_dns.exe vector is already covered by CVE-2008-1244.

CVE-2008-1242 belkin vulnerability CVSS: 10.0 10 Mar 2008, 17:44 UTC

The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user, a different vulnerability than CVE-2005-3802.

CVE-2008-1244 belkin vulnerability CVSS: 10.0 10 Mar 2008, 17:44 UTC

cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.

CVE-2008-1245 belkin vulnerability CVSS: 7.8 10 Mar 2008, 17:44 UTC

cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header.

CVE-2008-0403 belkin vulnerability CVSS: 5.5 23 Jan 2008, 12:00 UTC

The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.

CVE-2007-6040 belkin vulnerability CVSS: 5.0 20 Nov 2007, 19:46 UTC

The Belkin F5D7230-4 Wireless G Router allows remote attackers to cause a denial of service (degraded networking and logging) via a flood of TCP SYN packets, a related issue to CVE-1999-0116.

CVE-2007-3784 belkin vulnerability CVSS: 4.3 15 Jul 2007, 23:30 UTC

Cross-site scripting (XSS) vulnerability in the Belkin G Plus Router F5D7231-4 with firmware 4.05.03 allows remote attackers to inject arbitrary web script or HTML via a hostname of a DHCP client.

CVE-2005-4417 belkin vulnerability CVSS: 6.4 20 Dec 2005, 11:03 UTC

The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send arbitrary audio and possibly eavesdrop using the microphone via the Hands Free Audio Gateway and Headset profile.

CVE-2005-3802 belkin vulnerability CVSS: 5.1 24 Nov 2005, 11:03 UTC

Belkin F5D7232-4 and F5D7230-4 wireless routers with firmware 4.03.03 and 4.05.03, when a legitimate administrator is logged into the web management interface, allow remote attackers to access the management interface without authentication.

CVE-2005-2374 belkin vulnerability CVSS: 7.5 26 Jul 2005, 04:00 UTC

Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) web administration interfaces.

CVE-2005-0833 belkin vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.

CVE-2005-0835 belkin vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.

CVE-2002-1431 belkin vulnerability CVSS: 7.5 11 Apr 2003, 04:00 UTC

Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server.

CVE-2002-1811 belkin vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending several SNMP GetNextRequest requests.