CVE-2026-27516

8.1

Binardat · 10G08-0800GSM Network Switch

The Binardat 10G08-0800GSM network switch firmware exposes user passwords in plaintext via the administrative interface and HTTP responses, enabling credential theft.

Executive summary

A critical vulnerability in Binardat 10G08-0800GSM network switches allows authenticated attackers to retrieve plaintext user credentials, posing a severe risk to network integrity.

Vulnerability

This flaw involves the improper storage and transmission of sensitive information, categorized under CWE-201 and CWE-317. An attacker with low-level administrative access can intercept or view plaintext passwords through the device web interface or HTTP traffic.

Business impact

The exposure of administrative credentials grants unauthorized actors the ability to gain full control over network infrastructure. With a CVSS score of 8.1, the high severity reflects the potential for lateral movement, data interception, and total loss of confidentiality regarding network management access.

Remediation

Immediate Action: Contact the vendor immediately to obtain firmware updates that address credential exposure, as no specific patch version is currently identified.

Proactive Monitoring: Review all network management logs for anomalous HTTP requests targeting administrative endpoints or unexpected access patterns from authenticated user accounts.

Compensating Controls: Restrict access to the switch management interface to trusted management subnets only and implement strict egress filtering to prevent unauthorized monitoring of administrative traffic.

Exploitation status

Public Exploit Available: No (exploit_available unknown)

Analyst recommendation

Given the high CVSS severity, organizations utilizing Binardat 10G08-0800GSM switches must prioritize the mitigation of this credential exposure. Until a vendor-supplied firmware update is deployed, administrators should isolate these devices from untrusted network segments and enforce strictly controlled administrative access to minimize the risk of credential interception.

More Binardat CVEs

Sources

Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.