VYPR
Vendor

XikeStor

Products
3
CVEs
5
Across products
6
Status
Private

Products

3

Recent CVEs

5
  • CVE-2026-25072CriMar 7, 2026
    risk 0.64cvss 9.8epss 0.01

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using…

  • CVE-2026-25070CriMar 7, 2026
    risk 0.64cvss 9.8epss 0.03

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious…

  • CVE-2026-88263HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.01

    XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump…

  • CVE-2026-25071HigMar 7, 2026
    risk 0.49cvss 7.5epss 0.01

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint…

  • CVE-2026-25073MedMar 7, 2026
    risk 0.35cvss 5.4epss 0.00

    XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute…