CVE-2026-25071 PUBLISHED

XikeStor SKS8310-8X switch_config.src Missing Authentication

Assigner: VulnCheck
Reserved: 28.01.2026 Published: 07.03.2026 Updated: 07.03.2026

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint without credentials to retrieve sensitive configuration information including VLAN settings and IP addressing details.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Anhui Seeker Electronic Technology Co., LTD.
Product XikeStor SKS8310-8X
Versions Default: unknown
  • affected from 0 to 1.04.B07 (incl.)

Credits

  • Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc. finder
  • VulnCheck coordinator

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE