CRITICAL🇵🇱 Wersja polska

CVE-2026-32841

CVSS 9.2v4.0pub. 2026-03-17upd. 2026-05-26

Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.

🤖 AI Analysis
How it works

The vulnerability results from improper implementation of a global authentication flag mechanism. This flag is shared across all device clients — when any user successfully authenticates, the flag is set globally, causing the management interface to treat all subsequent users as authenticated. An attacker can thus gain administrative access without providing any credentials, provided that a legitimate user has previously logged in.

Impact

An attacker gains full administrative access to the device, enabling unauthorized password changes, malicious firmware installation, and modification of network switch configuration.

Mitigation & patch

Apply patches available from the manufacturer according to references. Until updating, it is recommended to isolate the device management interface from untrusted networks (e.g., through a dedicated management VLAN or firewall) and restrict interface access exclusively to trusted hosts.

Who is affected

Edimax GS-5008PL — firmware version 1.00.54 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Edimax Gs 5008pl

    HW
    Edimax
    all versions
  • Edimax Gs 5008pl Firmware

    OS
    Edimax
    ≤ 1.00.54
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-32838HIGH8.7same product

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface withou...

CVE-2026-32842HIGH7.1same product

Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that ...

CVE-2026-32839MEDIUM5.1same product

Oprogramowanie Edimax GS-5008PL w wersji 1.00.54 i wcześniejszych zawiera podatność CSRF pozwalającą zdalnym a...

CVE-2026-32840MEDIUM5.1same product

Oprogramowanie Edimax GS-5008PL w wersji 1.00.54 i wcześniejszych zawiera podatność stored XSS w skrypcie syst...

CVE-2025-1316CRITICAL9.3⚠ KEVPL ✓same vendor

Edimax IC-7100: Command Injection umożliwiający zdalny RCE