CVE-2026-32839

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:*

History

19 Mar 2026, 14:06

Type Values Removed Values Added
CPE cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:*
cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:*
First Time Edimax
Edimax gs-5008pl Firmware
Edimax gs-5008pl
References () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/ - () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/ - Product
References () https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/ - () https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/ - Product
References () https://www.vulncheck.com/advisories/edimax-gs-5008pl-csrf-via-management-cgi-endpoints - () https://www.vulncheck.com/advisories/edimax-gs-5008pl-csrf-via-management-cgi-endpoints - Third Party Advisory

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) La versión 1.00.54 y anteriores del firmware de Edimax GS-5008PL contienen una vulnerabilidad de falsificación de petición en sitios cruzados que permite a atacantes remotos realizar acciones administrativas no autorizadas induciendo a administradores con sesión iniciada a visitar páginas maliciosas. Los atacantes pueden explotar la falta de tokens anti-CSRF y de validación de peticiones para cambiar contraseñas, cargar firmware, reiniciar el dispositivo, realizar restablecimientos de fábrica o modificar configuraciones de red.

17 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 22:16

Updated : 2026-03-19 14:06


NVD link : CVE-2026-32839

Mitre link : CVE-2026-32839

CVE.ORG link : CVE-2026-32839


JSON object : View

Products Affected

edimax

  • gs-5008pl_firmware
  • gs-5008pl
CWE
CWE-352

Cross-Site Request Forgery (CSRF)