cbcvebase.

Edimax Technology Co Ltd Edimax Gs-5008Pl vulnerabilities

5 known vulnerabilities affecting edimax_technology_co_ltd/edimax_gs-5008pl.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-32841P2HIGHCVSS 8.1≤ 1.0.542026-03-17
CVE-2026-32841 [HIGH] CWE-1108 CVE-2026-32841: Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password chang
nvd
CVE-2026-32842P3MEDIUMCVSS 6.5≤ 1.0.542026-03-17
CVE-2026-32842 [MEDIUM] CWE-312 CVE-2026-32842: Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerabi Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative ac
nvd
CVE-2026-32839P3MEDIUMCVSS 6.5≤ 1.0.542026-03-17
CVE-2026-32839 [MEDIUM] CWE-352 CVE-2026-32839: Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerabili Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmwar
nvd
CVE-2026-32838P3MEDIUMCVSS 5.9≤ 1.0.542026-03-17
CVE-2026-32838 [MEDIUM] CWE-319 CVE-2026-32838: Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interf Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
nvd
CVE-2026-32840P4MEDIUMCVSS 5.4≤ 1.0.542026-03-17
CVE-2026-32840 [MEDIUM] CWE-79 CVE-2026-32840: Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerabil Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including sys
nvd
Edimax Technology Co Ltd Edimax Gs-5008Pl vulnerabilities | cvebase