CVE-2026-23678

8.8

Binardat · 10G08-0800GSM Network Switch

The Binardat 10G08-0800GSM network switch firmware is vulnerable to command injection via the traceroute diagnostic function in the web management interface.

Executive summary

An authenticated command injection vulnerability in Binardat 10G08-0800GSM network switches allows attackers to execute arbitrary commands, potentially leading to full device compromise.

Vulnerability

This is an OS Command Injection vulnerability (CWE-78) triggered by injecting malicious characters into the hostname parameter of the traceroute diagnostic function. The flaw requires an authenticated attacker with access to the web management interface to successfully execute commands.

Business impact

The ability to execute arbitrary CLI commands on network infrastructure poses a severe risk to organizational security, as an attacker could modify network traffic, disable security controls, or move laterally across the network. With a CVSS score of 8.8, this vulnerability is categorized as High, reflecting the potential for total loss of confidentiality, integrity, and availability of the affected switch.

Remediation

Immediate Action: Contact the vendor or monitor the official Binardat support portal for the release of a firmware update that addresses this command injection flaw.

Proactive Monitoring: Review web management interface access logs for suspicious activity, specifically monitoring for unusual input strings containing special characters within diagnostic function parameters.

Compensating Controls: Restrict access to the switch web management interface to trusted IP addresses only, and employ a Web Application Firewall (WAF) or network access control list to limit exposure of the management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of network hardware, organizations should treat this vulnerability with urgency. If a vendor patch is not yet available, administrators must isolate the management interface from untrusted networks immediately to mitigate the risk of exploitation.

More Binardat CVEs

Sources

Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.