CVE-2025-7086 | Belkin F9K1122 1.00.33 webs /goform/formPPTPSetup pptpUserName stack-based overflow (EUVD-2025-20143)
A vulnerability classified as critical has been found in Belkin F9K1122 1.00.33. Affected is the function formPPTPSetup of the file /goform/formPPTPSetup of the component webs. The manipulation of the argument pptpUserName leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-7086. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.