CVE-2026-32841 Details
Description
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.
An authentication bypass vulnerability has been identified in the Edimax GS-5008PL switch, affecting firmware versions through 1.00.54. This vulnerability allows unauthenticated attackers to access the management interface. Exploitation involves taking advantage of the global authentication flag mechanism, which grants administrative access without credentials after any user has authenticated. This unauthorized access could lead to unauthorized password changes, firmware uploads, and modifications of the device's configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1108 | Excessive Reliance on Global Variables | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| edimax gs-5008pl firmware | <= 1.00.54 |
CPE
Remediation
| |
| edimax gs-5008pl | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | Initial Analysis | [email protected] |
| Mar 17, 2026 | New CVE Received | [email protected] |