← Vulnerability feed

Vulnerability record · CVE-2026-27521 · published 24 February 2026

CVE-2026-27521: Binardat 10g08-0800gsm firmware improper restriction of authentication attempts vulnerability

Binardat · 10g08 0800gsm Firmware

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials.

6.9 CVSS 4.0 Medium EPSS 0.43% · top 65.3% CWE-307 · Improper restriction of authentication attempts
6.9CVSS 4.0 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-27507Binardat 10g08-0800gsm firmware hard-coded credentials vulnerabilityBinardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed …EPSS 0.54%9.3CVE-2026-27515Binardat 10g08-0800gsm firmware vulnerabilityBinardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web managemen…EPSS 0.47%8.7CVE-2026-27519Binardat 10g08-0800gsm firmware broken cryptographic algorithm vulnerabilityBinardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Bec…EPSS 0.27%8.7CVE-2026-27520Binardat 10g08-0800gsm firmware cleartext storage of sensitive data vulnerabilityBinardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded val…EPSS 0.28%8.7CVE-2026-23678Binardat 10g08-0800gsm firmware os command injection vulnerabilityBinardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnosti…EPSS 1.2%8.6CVE-2026-27516Binardat 10g08-0800gsm firmware vulnerabilityBinardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interfac…EPSS 0.26%5.1CVE-2026-27517Binardat 10g08-0800gsm firmware cross-site scripting vulnerabilityBinardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior reflect unsanitized user input in the web interface, allowing an atta…EPSS 0.25%5.1CVE-2026-27518Binardat 10g08-0800gsm firmware cross-site request forgery vulnerabilityBinardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior lack CSRF protections for state-changing actions in the administrativ…EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2026-27521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.