CVE-2026-27520 describes a critical information disclosure vulnerability in Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209. The vulnerability allows an attacker to recover plaintext user passwords by accessing Base64-encoded values stored in client-side cookies via the web interface. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a high-severity risk due to its network-based attack vector, low attack complexity, and high confidentiality impact, requiring no privileges or user interaction. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there is minimal community discussion, it is not present on the KEV catalog or Hot List, suggesting it is not a priority for immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= V300SP10260209CPE matchmatch criteria | cpe:2.3:o:binardat:10g08-0800gsm_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.