CVE-2026-32840: Edimax GS-5008PL <= 1.00.54 Stored XSS via Device Name
Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the systemnameset.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including systemdata.js are viewed by administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Edimax GS-5008PLto a version that resolves this vulnerability.Fixed in 1.00.54
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32840?
CVE-2026-32840 is considered a medium severity vulnerability due to its stored XSS nature.
How do I fix CVE-2026-32840?
To mitigate CVE-2026-32840, upgrade the Edimax GS-5008PL firmware to version 1.00.55 or later.
What is the impact of CVE-2026-32840?
CVE-2026-32840 allows attackers to inject arbitrary script code, potentially leading to session hijacking and data theft.
Which products are affected by CVE-2026-32840?
CVE-2026-32840 affects Edimax GS-5008PL devices running firmware version 1.00.54 and earlier.
Can CVE-2026-32840 be exploited remotely?
Yes, CVE-2026-32840 can be exploited remotely through malicious web requests targeting the vulnerable device.