PatchSiren cyber security CVE debrief
CVE-2026-32841 EDIMAX Technology Co., Ltd. CVE debrief
A critical authentication bypass vulnerability exists in Edimax GS-5008PL firmware versions 1.00.54 and prior. The flaw stems from a global authentication flag mechanism that fails to properly isolate session states between clients. Once any legitimate user authenticates to the device, the global flag is set, allowing subsequent unauthenticated attackers to access the management interface without credentials by leveraging this shared state. This enables complete administrative compromise including unauthorized password changes, firmware uploads, and configuration modifications. The vulnerability was published to the CVE database on March 17, 2026, and modified on May 26, 2026. No known exploitation in ransomware campaigns has been documented.
- Vendor
- EDIMAX Technology Co., Ltd.
- Product
- Edimax GS-5008PL
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-17
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-03-17
- Advisory updated
- 2026-05-26
Who should care
Network administrators managing Edimax GS-5008PL switches in enterprise, SMB, or industrial environments; security teams responsible for network infrastructure hardening; organizations with remote or distributed switch deployments where management interfaces may be exposed.
Technical summary
The Edimax GS-5008PL implements a global authentication flag that is shared across all client sessions rather than maintaining per-session authentication state. When any user successfully authenticates, this global flag is set to 'authenticated,' granting administrative access to any subsequent requestor regardless of credential presentation. The management interface fails to validate session-specific tokens or cookies, allowing unauthenticated attackers to exploit this state after legitimate administrator activity. This architectural flaw enables complete device compromise without valid credentials.
Defensive priority
critical
Recommended defensive actions
- Immediately isolate affected Edimax GS-5008PL switches from untrusted networks or internet exposure
- Restrict management interface access to dedicated administrative VLANs with strict ACLs
- Monitor for unauthorized management sessions or configuration changes on affected devices
- Contact Edimax for firmware update availability beyond version 1.00.54
- Implement network segmentation to limit lateral movement if compromise occurs
- Review device configurations for unauthorized changes if exposure is suspected
Evidence notes
Vulnerability confirmed through NVD CPE criteria (cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:* versionEndIncluding 1.00.54) and third-party advisory from VulnCheck. CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, and high impact to confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32841 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32841
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32841 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32841
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_legacy_switches/gs-5008pl/
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_legacy_products/
[email protected] - Product
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/edimax-gs-5008pl-global-authentication-state-across-all-clients
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.