CVE-2026-27517

B

inardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an attacker to inject and execute arbitrary JavaScript in the context of an authenticated user.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:binardat:10g08-0800gsm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:binardat:10g08-0800gsm:-:*:*:*:*:*:*:*

History

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 6.1

25 Feb 2026, 17:13

Type Values Removed Values Added
First Time Binardat
Binardat 10g08-0800gsm Firmware
Binardat 10g08-0800gsm
References () https://www.binardat.com/products/8-port-10-gigabit-sfp-managed-switch,-support-1g-sfp-and-10g-sfp-module,-160gbps-bandwidth,-l3-web-managed,-metal-fanless-fiber-binardat-network-switch - () https://www.binardat.com/products/8-port-10-gigabit-sfp-managed-switch,-support-1g-sfp-and-10g-sfp-module,-160gbps-bandwidth,-l3-web-managed,-metal-fanless-fiber-binardat-network-switch - Product
References () https://www.vulncheck.com/advisories/binardat-10g08-0800gsm-network-switch-xss - () https://www.vulncheck.com/advisories/binardat-10g08-0800gsm-network-switch-xss - Third Party Advisory
CPE cpe:2.3:o:binardat:10g08-0800gsm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:binardat:10g08-0800gsm:-:*:*:*:*:*:*:*

24 Feb 2026, 16:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 16:24

Updated : 2026-03-02 15:16


NVD link : CVE-2026-27517

Mitre link : CVE-2026-27517

CVE.ORG link : CVE-2026-27517


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')