CVE-2026-32838: Edimax GS-5008PL <= 1.00.54 Transmits Credentials Over Cleartext HTTP
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Edimax GS-5008PL web management interface (which uses cleartext HTTP in firmware versions 1.00.54 and prior) so it is not reachable from untrusted networks/hosts on the same network (e.g., allow only trusted admin IPs via network ACL/firewall, and ensure management is performed from a trusted network segment).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32838?
CVE-2026-32838 has been rated as a high severity vulnerability due to the risk of credential interception.
How do I fix CVE-2026-32838?
To fix CVE-2026-32838, upgrade the Edimax GS-5008PL firmware to version 1.00.55 or later which implements secure HTTPS connections.
What are the risks associated with CVE-2026-32838?
Exploiting CVE-2026-32838 allows attackers on the same network to intercept sensitive management credentials transmitted in cleartext.
Which devices are affected by CVE-2026-32838?
CVE-2026-32838 affects the Edimax GS-5008PL firmware versions up to and including 1.00.54.
Is CVE-2026-32838 a network vulnerability?
Yes, CVE-2026-32838 is a network vulnerability that can be exploited through eavesdropping on traffic within the same local network.