Impact
The Edimax GS‑5008PL firmware versions 1.00.54 and earlier contain an authentication bypass (CWE‑1108) that allows an unauthenticated attacker to access the management interface by exploiting the global authentication flag mechanism after any user logs in, granting full administrative control. This enables unauthorized password changes, firmware uploads, and configuration modifications, giving an attacker complete control over the device.
Affected Systems
Affected products are the Edimax GS‑5008PL switch from EDIMAX Technology Co., Ltd. Firmware versions 1.00.54 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to access the management interface, which can be done remotely via the default web UI. Once accessed, the attacker can manipulate the device as if they had authenticated credentials.
OpenCVE Enrichment