← volver
CVE-2026-32841

Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients

CVSS 9.2 CRITICALEPSS 0.6%CWE-1108
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.2EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
17 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →