PT-2026-25945 · Edimax · Edimax Gs-5008Pl
Kazuma Matsumoto
·
Published
2026-03-17
·
Updated
2026-03-18
·
CVE-2026-32839
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Edimax GS-5008PL firmware versions prior to 1.00.54
Description
The firmware does not properly protect against cross-site request forgery, potentially allowing remote attackers to perform unauthorized administrative actions. An attacker can induce logged-in administrators to visit malicious pages, exploiting the absence of anti-CSRF tokens and request validation. This could allow attackers to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
Recommendations
Update the firmware to a version newer than 1.00.54.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edimax Gs-5008Pl