Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an attacker to inject and execute arbitrary JavaScript in the context of an authenticated user.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
25 Feb 2026, 17:13
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:binardat:10g08-0800gsm_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:binardat:10g08-0800gsm:-:*:*:*:*:*:*:* |
|
| First Time |
Binardat 10g08-0800gsm
Binardat 10g08-0800gsm Firmware Binardat |
|
| References | () https://www.binardat.com/products/8-port-10-gigabit-sfp-managed-switch,-support-1g-sfp-and-10g-sfp-module,-160gbps-bandwidth,-l3-web-managed,-metal-fanless-fiber-binardat-network-switch - Product | |
| References | () https://www.vulncheck.com/advisories/binardat-10g08-0800gsm-network-switch-xss - Third Party Advisory |
24 Feb 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 16:24
Updated : 2026-02-25 17:13
NVD link : CVE-2026-27517
Mitre link : CVE-2026-27517
CVE.ORG link : CVE-2026-27517
JSON object : View
Products Affected
binardat
- 10g08-0800gsm_firmware
- 10g08-0800gsm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
