VYPR
Unrated severityNVD Advisory· Published Mar 17, 2026· Updated Mar 18, 2026

Edimax GS-5008PL <= 1.00.54 Stored XSS via Device Name

CVE-2026-32840

Description

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.

Affected products

2
  • Edimax/GS-5008PLllm-fuzzy
    Range: <=1.00.54
  • EDIMAX Technology Co., Ltd./Edimax GS-5008PLv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.