PT-2026-21758 · Binardat · 10G08-0800Gsm Network Switch
Kazuma Matsumoto
·
Published
2026-02-24
·
Updated
2026-02-25
·
CVE-2026-27520
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209
Description
The firmware stores a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Base64 encoding is reversible and does not provide confidentiality, allowing an attacker who can access the cookie value to recover the plaintext password.
Recommendations
Update to firmware version V300SP10260209 or later.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
10G08-0800Gsm Network Switch