CVE-2026-32838

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:*

History

19 Mar 2026, 14:08

Type Values Removed Values Added
References () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/ - () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/ - Product
References () https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/ - () https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/ - Product
References () https://www.vulncheck.com/advisories/edimax-gs-5008pl-transmits-credentials-over-cleartext-http - () https://www.vulncheck.com/advisories/edimax-gs-5008pl-transmits-credentials-over-cleartext-http - Third Party Advisory
CPE cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:*
cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:*
First Time Edimax
Edimax gs-5008pl Firmware
Edimax gs-5008pl

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) El firmware Edimax GS-5008PL versión 1.00.54 y anteriores utilizan HTTP en texto claro para la interfaz de gestión web sin implementar cifrado TLS o SSL. Atacantes en la misma red pueden interceptar el tráfico de gestión para capturar credenciales de administrador y datos de configuración sensibles.

17 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 22:16

Updated : 2026-03-19 14:08


NVD link : CVE-2026-32838

Mitre link : CVE-2026-32838

CVE.ORG link : CVE-2026-32838


JSON object : View

Products Affected

edimax

  • gs-5008pl_firmware
  • gs-5008pl
CWE
CWE-319

Cleartext Transmission of Sensitive Information