VYPR

SKS8310-8X

by XikeStor

CVEs (4)

  • CVE-2026-25072CriMar 7, 2026
    risk 0.64cvss 9.8epss 0.01

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using…

  • CVE-2026-25070CriMar 7, 2026
    risk 0.64cvss 9.8epss 0.03

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious…

  • CVE-2026-25071HigMar 7, 2026
    risk 0.49cvss 7.5epss 0.01

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint…

  • CVE-2026-25073MedMar 7, 2026
    risk 0.35cvss 5.4epss 0.00

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute…