CVE-2026-25071: Seekswan Zikestor SKS8310-8x Firmware

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint without credentials to retrieve sensitive configuration information including VLAN settings and IP addressing details.

Affected products

  • Seekswan Zikestor SKS8310-8x Firmware: up to and including 1.04.b07

Published 2026-03-07. Last modified 2026-06-17.