Description
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
Problem types
CWE-319 Cleartext transmission of sensitive information
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.edimax.com/...a/edimax/us/smb_legacy_switches/gs-5008pl/
www.edimax.com/...e_list/data/edimax/us/smb_legacy_products/
www.vulncheck.com/...ansmits-credentials-over-cleartext-http