Junglewise Threat Intelligence

CVE-2026-75124: PLANET GS-4210-16P2S V3 pre-authentication memory corruption

CVE-2026-75124 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: PLANET GS-4210-16P2S V3. Vendors: PLANET.

Executive brief

The PLANET GS-4210-16P2S V3 is a managed network switch used in corporate environments to control traffic between servers and endpoints. A pre-authentication vulnerability in its web management interface allows an unauthenticated attacker to send a specially crafted web request that crashes the management service, rendering the switch unmanageable. An attacker could exploit this to disrupt network operations or potentially gain deeper system access.

Technical details

This vulnerability is a classic buffer overflow (CWE-120) in the HTTP query-string parsing logic of the dispatcher.cgi web interface. The vulnerable _readHttpParam function reads an oversized GET request parameter without ensuring proper NUL termination, then passes the data to parse_query_string where it is processed into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to /cgi-bin/dispatcher.cgi to trigger denial of service or memory corruption. No authentication is required; the network vector is direct HTTP. A patch is available in firmware version 3.441b260626 and later.

Affected products

  • PLANET GS-4210-16P2S V3 before 3.441b260626

Timeline

  • 2026-08-28: disclosed

References

Related threats