Published:2026/09/16 Last Updated:2026/09/16
JVN#45281119
XikeStor Layer3 switches miss authentication for downloading configuration data
Overview
XikeStor Layer3 switches miss authentication for downloading configuration data.
Products Affected
- SKS8310-8X versions prior to V1.04.B09
- SKS8300-8T versions prior to V1.04.B09
- SKS8300-12E2T2X versions prior to V1.04.B09
Description
XikeStor Layer3 switches contain the vulnerability listed below.
- Missing authentication for downloading configuration (CWE-306)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
- CVE-2026-88263
Impact
Confidential information, such as network configurations or passwords, may be retrieved by an unauthenticated attacker.
This allows the attacker to operate the affected product improperly or to exploit the affected product as a jump host.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| XikeStor | Security Advisory |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-88263 |
| JVN iPedia |
JVNDB-2026-000134 |