Description
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the web GUI of certain Murrelektronik Xelity switches. When an authenticated administrator uses the "Copy learned MAC Addresses" feature, the system logs the MAC addresses in its internal table. Due to improper error handling, an unauthenticated attacker with network reach to the GUI can view those logs through browser developer tools. This permits leakage of MAC addresses from the switch, which can aid network mapping and reconnaissance activities. The underlying weakness is classified as CWE‑209 – Information Exposure Through Error Messages.

Affected Systems

The affected line of products includes a range of Murrelektronik Xelity switches, such as Xelity 10 TX IP67 M FE, Xelity 8 TX M GE, Xelity 6 TX M GE, and others enumerated in the vendor list. All devices running firmware version V2.1.0 are potentially vulnerable, as the firmware identifier appears in the CPE strings. No other version or vendor information was supplied.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate impact. The EPSS score is unavailable, but the attacker only needs unauthenticated network access to the web interface, a readily achievable condition in most environments. The vulnerability is not listed in the CISA KEV catalog. Because the exposed data is logged MAC addresses, the risk is primarily in providing an attacker with additional network intelligence. Exploitation would involve a trivial action of accessing the admin interface via a browser, then inspecting logged data through developer tools. No special privileges or advanced capabilities are required beyond network reach.

Generated by OpenCVE AI on August 24, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify if a firmware update that fixes this issue has been released and upgrade the switches if possible.
  • Restrict access to the web‑based management console to trusted management networks, VPNs, or dedicated secure VLANs so that only authorized personnel can reach it.
  • If an immediate patch is unavailable, disable or remove the "Copy learned MAC Addresses" function in the GUI to stop storing the addresses in the log.

Generated by OpenCVE AI on August 24, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Title Information Disclosure via 'Copy learned MAC Addresses' Function
First Time appeared Murrelektronik
Murrelektronik xelity Firmware
Weaknesses CWE-209
CPEs cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58820:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58821:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58822:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58823:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58824:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58825:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58826:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58827:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58840:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58841:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58842:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58843:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58844:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58845:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58847:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58850:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58851:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58852:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58853:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58854:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58855:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58857:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58860:*
Vendors & Products Murrelektronik
Murrelektronik xelity Firmware
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Murrelektronik Xelity Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-24T06:47:58.406Z

Reserved: 2026-05-08T13:56:01.059Z

Link: CVE-2026-8173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T07:16:54.570

Modified: 2026-08-24T07:16:54.570

Link: CVE-2026-8173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T08:30:14Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information