CVE-2026-27516
8.1Binardat · 10G08-0800GSM Network Switch
The Binardat 10G08-0800GSM network switch firmware exposes user passwords in plaintext via the administrative interface and HTTP responses, enabling credential theft.
Executive summary
A critical vulnerability in Binardat 10G08-0800GSM network switches allows authenticated attackers to retrieve plaintext user credentials, posing a severe risk to network integrity.
Vulnerability
This flaw involves the improper storage and transmission of sensitive information, categorized under CWE-201 and CWE-317. An attacker with low-level administrative access can intercept or view plaintext passwords through the device web interface or HTTP traffic.
Business impact
The exposure of administrative credentials grants unauthorized actors the ability to gain full control over network infrastructure. With a CVSS score of 8.1, the high severity reflects the potential for lateral movement, data interception, and total loss of confidentiality regarding network management access.
Remediation
Immediate Action: Contact the vendor immediately to obtain firmware updates that address credential exposure, as no specific patch version is currently identified.
Proactive Monitoring: Review all network management logs for anomalous HTTP requests targeting administrative endpoints or unexpected access patterns from authenticated user accounts.
Compensating Controls: Restrict access to the switch management interface to trusted management subnets only and implement strict egress filtering to prevent unauthorized monitoring of administrative traffic.
Exploitation status
Public Exploit Available: No (exploit_available unknown)
Analyst recommendation
Given the high CVSS severity, organizations utilizing Binardat 10G08-0800GSM switches must prioritize the mitigation of this credential exposure. Until a vendor-supplied firmware update is deployed, administrators should isolate these devices from untrusted network segments and enforce strictly controlled administrative access to minimize the risk of credential interception.
More Binardat CVEs
Sources
Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.