CVE-2026-27521

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials.

Credits

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.

References