VYPR
Unrated severityNVD Advisory· Published Mar 17, 2026· Updated Mar 18, 2026

Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints

CVE-2026-32839

Description

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.

Affected products

2
  • Edimax/GS-5008PLllm-create
    Range: <=1.00.54
  • EDIMAX Technology Co., Ltd./Edimax GS-5008PLv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.