SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-8173

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The web GUI of certain Murrelektronik Xelity switches is vulnerable due to improper error message handling, allowing unauthenticated attackers with network access to extract logged MAC addresses using browser developer tools. This exposure can lead to unauthorized network reconnaissance, potentially facilitating further attacks. Organizations using these switches should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-8173
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.