← Back

Zikestor Sks8310 8x Firmware

zikestor_sks8310-8x_firmware

Vendor: Seekswan • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Seekswan
1Zikestor Sks8310 8x Firmware
Mar 12, 2026
Mar 7, 2026
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name f...Show more
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser when the stored value is viewed due to improper output encoding.Show less
1Seekswan
1Zikestor Sks8310 8x Firmware
Mar 12, 2026
Mar 7, 2026
8.6 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated session...Show more
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using insufficiently random cookie values and exploit exposed session parameters in URLs to gain unauthorized access to authenticated user sessions.Show less
1Seekswan
1Zikestor Sks8310 8x Firmware
Mar 12, 2026
Mar 7, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device co...Show more
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint without credentials to retrieve sensitive configuration information including VLAN settings and IP addressing details.Show less
1Seekswan
1Zikestor Sks8310 8x Firmware
Mar 12, 2026
Mar 7, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary...Show more
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious commands through the destIp parameter to achieve remote code execution with root privileges on the network switch.Show less