Vulnerability Description
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an authenticated attacker with access to the web interface can execute arbitrary CLI commands on the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Binardat | 10G08-0800Gsm Firmware | <= V300SP10260209 |
| Binardat | 10G08-0800Gsm | - |
Related Weaknesses (CWE)
References
- https://www.binardat.com/products/8-port-10-gigabit-sfp-managed-switch,-support-Product
- https://www.vulncheck.com/advisories/binardat-10g08-0800gsm-network-switch-traceThird Party Advisory
FAQ
What is CVE-2026-23678?
CVE-2026-23678 is a vulnerability with a CVSS score of 8.8 (HIGH). Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management in...
How severe is CVE-2026-23678?
CVE-2026-23678 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-23678?
Check the references section above for vendor advisories and patch information. Affected products include: Binardat 10G08-0800Gsm Firmware, Binardat 10G08-0800Gsm.