CVE-2026-32838
7.5Edimax · GS-5008PL
Edimax GS-5008PL firmware versions 1.00.54 and prior transmit management credentials over cleartext HTTP, allowing network-based attackers to intercept sensitive configuration data and login credentials.
Executive summary
The Edimax GS-5008PL firmware utilizes insecure cleartext transmission for its management interface, exposing administrative credentials to interception by local network attackers.
Vulnerability
This vulnerability involves the use of cleartext HTTP for web management without TLS or SSL encryption, allowing unauthenticated attackers on the same network to perform credential sniffing.
Business impact
The lack of encryption for the management interface presents a significant risk to network integrity. An attacker who successfully captures administrator credentials can gain full control over the network switch, potentially leading to unauthorized traffic monitoring, network segment compromise, or total loss of device availability. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to protect sensitive infrastructure management paths.
Remediation
Immediate Action: Restrict access to the management interface by placing the device on a dedicated, isolated management VLAN and limiting access to trusted IP addresses only.
Proactive Monitoring: Monitor network traffic for unusual HTTP requests directed toward the switch management IP address and review logs for unauthorized login attempts.
Compensating Controls: Deploy a secondary authentication layer or VPN access for the management network to ensure that administrative traffic is encrypted before reaching the vulnerable device.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing the Edimax GS-5008PL should assume that the management interface is insecure and immediately restrict network access to the device. Since a specific patch is not currently confirmed, prioritize the implementation of network-level segmentation to prevent unauthorized actors from reaching the management interface. Continue to monitor official vendor channels for firmware updates that implement mandatory TLS encryption for the web interface.
More Edimax CVEs
Sources
Originally found and disclosed by Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc., per the CVE Program record.