CVE-2026-27520: Binardat 10g08-0800gsm Firmware
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.
Affected products
- Binardat 10g08-0800gsm Firmware: up to and including V300SP10260209
Published 2026-02-24. Last modified 2026-06-17.