216.73.217.22

CVE-2026-27520

· Published 24/02/2026 16:24 · Modified 25/02/2026 17:25

Labels: CVE-2026-27520 2026-02-24CVE-2026-27520CWE-312[email protected]

Essential information

Published
24/02/2026 16:24
Modified
25/02/2026 17:25
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
binardat / 10g08-0800gsm firmware cpe:2.3:o:binardat:10g08-0800gsm_firmware:*:*:*:*:*:*:*:*
binardat / 10g08-0800gsm cpe:2.3:h:binardat:10g08-0800gsm:-:*:*:*:*:*:*:*

References