CVE-2026-23678
HIGHBinardat 10G08-0800GSM V300SP10260209 - Command Injection
Title source: llmDescription
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an authenticated attacker with access to the web interface can execute arbitrary CLI commands on the device.
References (2)
Scores
CVSS v3
8.8
EPSS
0.0033
EPSS Percentile
55.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (1)
binardat/10g08-0800gsm_firmware
< V300SP10260209
Timeline
Published
Feb 24, 2026
Tracked Since
Feb 24, 2026