CVE-2026-27515
critical · 9.3Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session IDs and hijack authenticated sessions.
9.3
CVSS
0.3%
EPSS (exploit prob.)
25th
EPSS percentile
2026-02-24
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-330
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| binardat | 10g08-0800gsm_firmware | <= V300SP10260209 |
| binardat | 10g08-0800gsm | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-27515