CVE-2026-32841CWE-1108

Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients

Critical · published March 17, 2026

CVSS v4.0
9.2
EPSS
1%
Percentile
46.2
In the wild
Unconfirmed
What it is

Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.

The record
Technical detail
CVSS v4.0
9.2 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00596 · 46.2th percentile
Weakness
CWE-1108 · Excessive Reliance on Global Variables
Published
2026-03-17T21:41Z
EPSS history
Timeline
  • 17 MAR 21:41Z
    Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients
    cvelistv5