PT-2026-25946 · Edimax · Edimax Gs-5008Pl
Kazuma Matsumoto
·
Published
2026-03-17
·
Updated
2026-03-18
·
CVE-2026-32840
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Edimax GS-5008PL firmware versions prior to 1.00.54
Description
The Edimax GS-5008PL firmware contains a stored cross-site scripting issue in the
system name set.cgi script. Attackers can inject arbitrary script code by manipulating the sysName parameter. A crafted POST request with a malicious script payload is sent, and the payload executes when management pages, including system data.js, are viewed by administrators.Recommendations
Update the firmware to a version newer than 1.00.54.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edimax Gs-5008Pl