Vulnerability Description
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Edimax | Gs-5008Pl Firmware | <= 1.00.54 |
| Edimax | Gs-5008Pl | - |
Related Weaknesses (CWE)
References
- https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/us/smb_Product
- https://www.edimax.com/edimax/merchandise/merchandise_list/data/edimax/us/smb_leProduct
- https://www.vulncheck.com/advisories/edimax-gs-5008pl-transmits-credentials-overThird Party Advisory
FAQ
What is CVE-2026-32838?
CVE-2026-32838 is a vulnerability with a CVSS score of 7.5 (HIGH). Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept manageme...
How severe is CVE-2026-32838?
CVE-2026-32838 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-32838?
Check the references section above for vendor advisories and patch information. Affected products include: Edimax Gs-5008Pl Firmware, Edimax Gs-5008Pl.