Description

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.

INFO

Published Date :

2026-03-17T21:42:08.065Z

Last Modified :

2026-03-18T20:09:56.986Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2026-32840 vulnerability.

Vendors Products
Edimax
  • Gs-5008pl
  • Gs-5008pl Firmware
Edimax Technology
  • Edimax Gs-5008pl

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact