CVE-2026-32838
Severity CVSS v4.0:
HIGH
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
17/03/2026
Last modified:
19/03/2026
Description
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:edimax:gs-5008pl_firmware:*:*:*:*:*:*:*:* | 1.00.54 (including) | |
| cpe:2.3:h:edimax:gs-5008pl:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



