CVE-2026-27520
7.5Binardat · 10G08-0800GSM Network Switch
Binardat 10G08-0800GSM switches store user passwords in Base64-encoded browser cookies, allowing unauthenticated attackers to recover credentials via interception or local access.
Executive summary
The Binardat 10G08-0800GSM network switch firmware is vulnerable to cleartext credential exposure, posing a significant risk of unauthorized administrative access.
Vulnerability
This vulnerability involves the insecure storage of sensitive information, specifically user passwords, within client-side cookies. The application uses reversible Base64 encoding, which allows an unauthenticated attacker to retrieve and decode the password directly from the cookie.
Business impact
The compromise of administrative credentials on a network switch can lead to full device takeover, enabling attackers to intercept network traffic, modify configurations, or pivot to internal segments. With a CVSS score of 7.5, this flaw represents a high risk to network integrity and confidentiality, as it facilitates unauthorized access without requiring prior system knowledge or authentication.
Remediation
Immediate Action: Update the switch firmware to version V300SP10260209 or later to implement secure cookie handling practices.
Proactive Monitoring: Review web interface access logs for unusual patterns, and monitor for unauthorized attempts to access or intercept browser cookies associated with the switch management interface.
Compensating Controls: Implement a Web Application Firewall or restrict management interface access to specific, trusted management VLANs or IP addresses to limit the exposure of the vulnerable cookie to potential attackers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the ease of extracting credentials from the Base64-encoded cookie, this vulnerability poses a clear and present danger to network infrastructure. Administrators should prioritize the firmware update on all affected Binardat devices to ensure that credentials are no longer exposed in browser sessions. If patching is not immediately feasible, ensure the management interface is not accessible from public or untrusted network segments.
More Binardat CVEs
Sources
Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.