Loading
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can recover the plaintext password.
Use CWE-312, Binardat vendor hub and 10g08-0800gsm Firmware product page to widen CVE-2026-27520 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-27515, CVE-2026-27507 and CVE-2026-27519 for nearby disclosures in the same product family.