Gs 5008pl Edimax Gs 5008pl

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Edimax Gs 5008pl.

By the Year

In 2026 there have been 5 vulnerabilities in Edimax Gs 5008pl with an average score of 7.0 out of ten.

Year Vulnerabilities Average Score
2026 5 7.04

It may take a day or so for new Gs 5008pl vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Edimax Gs 5008pl Security Vulnerabilities

Edimax GS-5008PL <1.00.54 Cleartext HTTP Management Interface
CVE-2026-32838 8.7 - High - March 17, 2026

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.

Cleartext Transmission of Sensitive Information

Edimax GS-5008PL CSRF in firmware 1.00.54 allows admin actions
CVE-2026-32839 5.1 - Medium - March 17, 2026

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.

Session Riding

Edimax GS-5008PL <1.00.54 Stored XSS in system_name_set.cgi
CVE-2026-32840 5.1 - Medium - March 17, 2026

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.

XSS

Edimax GS5008PL <=1.00.54 Insecure Credential Store via config.bin Backup
CVE-2026-32842 7.1 - High - March 17, 2026

Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access.

Cleartext Storage of Sensitive Information

Edimax GS-5008PL Auth Bypass <1.00.54
CVE-2026-32841 9.2 - Critical - March 17, 2026

Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.

Excessive Reliance on Global Variables

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Edimax Gs 5008pl or by Edimax? Click the Watch button to subscribe.

Edimax
Vendor

subscribe