CVE-2026-32841
9.2
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.
Affected (1)
Products: Edimax: Gs 5008pl Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.00.54 |
| Running on/with | Platform Versions |
|---|---|
Edimax Gs 5008pl | All versions |
References (3)
Source: disclosure@vulncheck.com
Product
Source: disclosure@vulncheck.com
Product
https://www.vulncheck.com/advisories/edimax-gs-5008pl-global-authentication-state-across-all-clients
Source: disclosure@vulncheck.com
Third Party Advisory
Timeline
No history available yet.