Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session IDs and hijack authenticated sessions.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
25 Feb 2026, 17:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.binardat.com/products/8-port-10-gigabit-sfp-managed-switch,-support-1g-sfp-and-10g-sfp-module,-160gbps-bandwidth,-l3-web-managed,-metal-fanless-fiber-binardat-network-switch - Product | |
| References | () https://www.vulncheck.com/advisories/binardat-10g08-0800gsm-network-switch-predictable-session-identifiers - Third Party Advisory | |
| First Time |
Binardat 10g08-0800gsm
Binardat 10g08-0800gsm Firmware Binardat |
|
| CPE | cpe:2.3:o:binardat:10g08-0800gsm_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:binardat:10g08-0800gsm:-:*:*:*:*:*:*:* |
24 Feb 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 16:24
Updated : 2026-02-25 17:25
NVD link : CVE-2026-27515
Mitre link : CVE-2026-27515
CVE.ORG link : CVE-2026-27515
JSON object : View
Products Affected
binardat
- 10g08-0800gsm_firmware
- 10g08-0800gsm
CWE
CWE-330
Use of Insufficiently Random Values
