VYPR
Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 27, 2026

Binardat 10G08-0800GSM Network Switch Traceroute CLI Command Injection

CVE-2026-23678

Description

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an authenticated attacker with access to the web interface can execute arbitrary CLI commands on the device.

Affected products

2
  • Range: <= V300SP10260209
  • Binardat Ltd./10G08-0800GSM Network Switchv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.