← Volver a CVEs
CVE-2026-32842
MEDIUM6.5
Descripcion
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access.
Detalles CVE
Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado3/17/2026
Ultima modificacion3/19/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
edimax:gs-5008pledimax:gs-5008pl_firmware
Debilidades (CWE)
CWE-312
Referencias
https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/(disclosure@vulncheck.com)
https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/edimax-gs-5008pl-admin-credentials-stored-in-cleartext(disclosure@vulncheck.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.