Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.
The vulnerability results from improper implementation of a global authentication flag mechanism. This flag is shared across all device clients — when any user successfully authenticates, the flag is set globally, causing the management interface to treat all subsequent users as authenticated. An attacker can thus gain administrative access without providing any credentials, provided that a legitimate user has previously logged in.
An attacker gains full administrative access to the device, enabling unauthorized password changes, malicious firmware installation, and modification of network switch configuration.
Apply patches available from the manufacturer according to references. Until updating, it is recommended to isolate the device management interface from untrusted networks (e.g., through a dedicated management VLAN or firewall) and restrict interface access exclusively to trusted hosts.
Edimax GS-5008PL — firmware version 1.00.54 and earlier
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEdimax Gs 5008pl
HWEdimaxall versionsEdimax Gs 5008pl Firmware
OSEdimax≤ 1.00.54
Related vulnerabilities
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface withou...
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that ...
Oprogramowanie Edimax GS-5008PL w wersji 1.00.54 i wcześniejszych zawiera podatność CSRF pozwalającą zdalnym a...
Oprogramowanie Edimax GS-5008PL w wersji 1.00.54 i wcześniejszych zawiera podatność stored XSS w skrypcie syst...
Edimax IC-7100: Command Injection umożliwiający zdalny RCE