VYPR
Vendor

Belkin

Belkin International, Inc., is an American consumer electronics company headquartered in El Segundo, California. It produces mobile and computer connectivity devices and peripherals for consumer and commercial use. These include wireless chargers, power banks, charging cables, data cables, audio and video adapters, headphones, earbuds, screen protectors and cases, surge protectors, docking stations and data hubs, secure KVM switches and network cables.

Founded 1983
Products
65
CVEs
103
Across products
148
Status
Private

Products

65
View all 65 products →

Recent CVEs

103
View all 103 CVEs →
  • CVE-2019-12780CriJun 10, 2019
    risk 0.72cvss 9.8epss 0.72

    The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

  • CVE-2013-2748CriJan 28, 2020
    risk 0.68cvss 9.8epss 0.13

    Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

  • CVE-2018-1143CriApr 19, 2018
    risk 0.68cvss 9.8epss 0.55

    A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi.

  • CVE-2025-8730CriAug 8, 2025
    risk 0.67cvss 9.8epss 0.03

    A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The…

  • CVE-2020-35713CriDec 26, 2020
    risk 0.66cvss 9.8epss 0.33

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

  • CVE-2018-1145CriApr 19, 2018
    risk 0.66cvss 9.8epss 0.25

    A remote unauthenticated user can overflow a stack buffer in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.

  • CVE-2019-16340CriNov 21, 2019
    risk 0.65cvss 9.8epss 0.19

    Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.

  • CVE-2018-6692CriAug 21, 2018
    risk 0.65cvss 10.0epss 0.04

    Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet.

  • CVE-2009-20009CriAug 30, 2025
    risk 0.64cvss epss 0.01

    Belkin Bulldog Plus version 4.0.2 build 1219 contains a stack-based buffer overflow vulnerability in its web service authentication handler. When a specially crafted HTTP request is sent with an oversized Authorization header, the application fails to properly validate the input…

  • CVE-2023-27217CriMay 18, 2023
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request.

  • CVE-2022-30105CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.03

    In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters],…

  • CVE-2013-7173CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Belkin n750 routers have a buffer overflow.

  • CVE-2013-3091CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.04

    An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

  • CVE-2013-3088CriDec 26, 2019
    risk 0.64cvss 9.8epss 0.02

    Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

  • CVE-2013-3085CriDec 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

  • CVE-2018-1144CriApr 19, 2018
    risk 0.64cvss 9.8epss 0.07

    A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.

  • CVE-2015-5989CriDec 31, 2015
    risk 0.64cvss 9.8epss 0.03

    Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.

  • CVE-2015-5988CriDec 31, 2015
    risk 0.64cvss 9.8epss 0.03

    The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.

  • CVE-2025-7093HigJul 6, 2025
    risk 0.58cvss 8.8epss 0.04

    A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. Affected by this vulnerability is the function formSetLanguage of the file /goform/formSetLanguage of the component webs. The manipulation of the argument webpage leads to stack-based buffer…

  • CVE-2025-7092HigJul 6, 2025
    risk 0.58cvss 8.8epss 0.04

    A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. This vulnerability affects the function formWlanSetupWPS of the file /goform/formWlanSetupWPS of the component webs. The manipulation of the argument wps_enrolee_pin/webpage leads to stack-based…