Executive brief
XikeStor Layer3 switches are network infrastructure devices used to manage and route traffic in enterprise environments. An unauthenticated attacker can download the device's configuration file without providing credentials, exposing sensitive information including network settings and account passwords. This enables attackers to compromise network operations, impersonate legitimate administrators, or use the compromised switch as a pivot point to attack other systems on the network.
Technical details
The vulnerability is a missing authentication check (CWE-306) in the configuration file download function of XikeStor Layer3 switches. The management interface fails to validate that a user is authenticated before allowing download of the device configuration file. An attacker with network access to the switch management IP address can directly request the configuration file without credentials. The configuration file contains sensitive data including network configurations, management credentials, and system settings. Affected firmware versions prior to V1.04.B09 are vulnerable; users should update to the latest firmware version released on April 28, 2026.
Affected products
- XikeStor SKS8310-8X prior to V1.04.B09
- XikeStor SKS8300-8T prior to V1.04.B09
- XikeStor SKS8300-12E2T2X prior to V1.04.B09
Timeline
- 2026-09-16: disclosed
- 2026-04-28: patched: Firmware fix released; April 28, 2026 date likely refers to advisory publication or availability