CVE-2026-32842 PUBLISHED

Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext

Assigner: VulnCheck
Reserved: 16.03.2026 Published: 17.03.2026 Updated: 17.03.2026

Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor EDIMAX Technology Co., Ltd.
Product Edimax GS-5008PL
Versions Default: unknown
  • affected from 0 to 1.00.54 (incl.)

Credits

  • Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc. finder

References

Problem Types

  • CWE-312 Cleartext storage of sensitive information CWE