CVE-2026-32839: Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints
Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Edimax GS-5008PLto a version that resolves this vulnerability.Fixed in 1.00.54
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32839?
CVE-2026-32839 is considered a medium severity vulnerability due to its potential for unauthorized administrative actions.
How do I fix CVE-2026-32839?
To fix CVE-2026-32839, update the Edimax GS-5008PL firmware to a version later than 1.00.54.
What type of vulnerability is CVE-2026-32839?
CVE-2026-32839 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2026-32839?
Users of Edimax GS-5008PL with firmware version 1.00.54 or earlier are affected by CVE-2026-32839.
What actions can an attacker perform using CVE-2026-32839?
An attacker can perform unauthorized administrative actions by tricking logged-in administrators to access a malicious page.