Published:2026/09/16  Last Updated:2026/09/16

JVN#45281119
XikeStor Layer3 switches miss authentication for downloading configuration data

Overview

XikeStor Layer3 switches miss authentication for downloading configuration data.

Products Affected

  • SKS8310-8X versions prior to V1.04.B09
  • SKS8300-8T versions prior to V1.04.B09
  • SKS8300-12E2T2X versions prior to V1.04.B09

Description

XikeStor Layer3 switches contain the vulnerability listed below.

  • Missing authentication for downloading configuration (CWE-306)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
    • CVE-2026-88263

Impact

Confidential information, such as network configurations or passwords, may be retrieved by an unauthenticated attacker.
This allows the attacker to operate the affected product improperly or to exploit the affected product as a jump host.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
XikeStor Security Advisory

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-88263
JVN iPedia JVNDB-2026-000134