Binardat
Binardat 10g08-0800gsm Firmware: vulnerabilidades y CVE
Binardat 10g08-0800gsm Firmware tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses9
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27521 | Media (6.9) | 0.43% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials. |
| CVE-2026-27520 | Alta (8.7) | 0.28% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and… |
| CVE-2026-27519 | Alta (8.7) | 0.27% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker can decrypt protected… |
| CVE-2026-27518 | Media (5.1) | 0.15% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing actions in the administrative interface. An attacker can trick an authenticated administrator into… |
| CVE-2026-27517 | Media (5.1) | 0.25% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an attacker to inject and execute arbitrary JavaScript in the context of an… |
| CVE-2026-27516 | Alta (8.6) | 0.26% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing recovery of valid credentials. |
| CVE-2026-27515 | Crítica (9.3) | 0.47% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session IDs and hijack… |
| CVE-2026-27507 | Crítica (9.3) | 0.54% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows full administrative… |
| CVE-2026-23678 | Alta (8.7) | 1.2% | — | 24 feb 2026 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.