Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Edimax Technology
Edimax Technology edimax Gs-5008pl |
|
| Vendors & Products |
Edimax Technology
Edimax Technology edimax Gs-5008pl |
Tue, 17 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 17 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access. | |
| Title | Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-17T21:41:55.905Z
Updated: 2026-03-17T21:46:59.781Z
Reserved: 2026-03-16T18:11:41.758Z
Link: CVE-2026-32842
No data.
Status : Awaiting Analysis
Published: 2026-03-17T22:16:15.227
Modified: 2026-03-18T14:52:44.227
Link: CVE-2026-32842
No data.