CVE-2025-9379 Details
Description
A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an unknown functionality of the component Firmware Update Handler. This manipulation causes insufficient verification of data authenticity. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in the Belkin AX1800 WiFi 6 router, specifically in firmware version 1.1.00.016. The issue arises in the Firmware Update Handler component, where the integrity verification process of the new firmware is inadequate. The router uses CRC32 checks to validate firmware updates, a method that can be easily bypassed. Attackers could craft a malicious firmware file that matches the CRC32 value of a legitimate update, allowing them to replace the genuine firmware with their own. This flaw could lead to arbitrary code execution or a denial-of-service condition on the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 24, 2025CISA-ADP
Assessed Aug 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Belkin/AX1800.md | [email protected] | Technical Description |
| https://vuldb.com/?ctiid.321212 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.321212 | [email protected] | AdvisoryPartial Content |
| https://vuldb.com/?submit.628641 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Belkin AX1800 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 24, 2025 | New CVE Received | [email protected] |
Volerion