CVE-2026-27517 PUBLISHED

Binardat 10G08-0800GSM Network Switch XSS

Assigner: VulnCheck
Reserved: 19.02.2026 Published: 24.02.2026 Updated: 24.02.2026

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an attacker to inject and execute arbitrary JavaScript in the context of an authenticated user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Binardat Ltd.
Product 10G08-0800GSM Network Switch
Versions Default: unaffected
  • affected from 0 to V300SP10260209 (incl.)

Credits

  • Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc. finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE