CVE-2026-32840

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:*

History

19 Mar 2026, 14:04

Type Values Removed Values Added
References () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/ - () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/ - Product
References () https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/ - () https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/ - Product
References () https://www.vulncheck.com/advisories/edimax-gs-5008pl-stored-xss-via-device-name - () https://www.vulncheck.com/advisories/edimax-gs-5008pl-stored-xss-via-device-name - Third Party Advisory
First Time Edimax
Edimax gs-5008pl Firmware
Edimax gs-5008pl
CPE cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:*
cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:*

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Edimax GS-5008PL firmware versión 1.00.54 y anteriores contienen una vulnerabilidad de cross-site scripting almacenado en el script system_name_set.cgi que permite a los atacantes inyectar código de script arbitrario manipulando el parámetro sysName. Los atacantes pueden enviar una solicitud POST manipulada con una carga útil de script malicioso que se ejecuta cuando las páginas de administración, incluyendo system_data.js, son vistas por los administradores.

17 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 22:16

Updated : 2026-03-19 14:04


NVD link : CVE-2026-32840

Mitre link : CVE-2026-32840

CVE.ORG link : CVE-2026-32840


JSON object : View

Products Affected

edimax

  • gs-5008pl_firmware
  • gs-5008pl
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')