PT-2026-25945 · Edimax · Edimax Gs-5008Pl

Kazuma Matsumoto

·

Published

2026-03-17

·

Updated

2026-03-18

·

CVE-2026-32839

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Edimax GS-5008PL firmware versions prior to 1.00.54
Description The firmware does not properly protect against cross-site request forgery, potentially allowing remote attackers to perform unauthorized administrative actions. An attacker can induce logged-in administrators to visit malicious pages, exploiting the absence of anti-CSRF tokens and request validation. This could allow attackers to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
Recommendations Update the firmware to a version newer than 1.00.54.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2026-03527
CVE-2026-32839

Affected Products

Edimax Gs-5008Pl