Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.2epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
EDIMAX Technology Co., Ltd. · Edimax GS-5008PLReferences
https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/https://www.vulncheck.com/advisories/edimax-gs-5008pl-global-authentication-state-across-all-clients