Executive brief
The PLANET GS-4210-16P2S V3 is a managed Gigabit switch used to connect and manage network devices. An authenticated administrator can trigger a crash in the web management interface by sending a specially crafted request, temporarily disabling remote access to configure the switch until the service restarts.
Technical details
A null pointer dereference vulnerability (CWE-476) exists in the web_poe_alive_rmtip_post handler within /cgi-bin/dispatcher.cgi. The handler dereferences the rmtIP POST parameter without first verifying it is present in the request. An authenticated attacker with administrator-level web-management privileges can send a POST request to the dispatcher.cgi endpoint (cmd=9223) that omits the rmtIP parameter, causing the CGI process to crash. The attack requires valid authentication credentials to reach the vulnerable code path. Successful exploitation results in denial of service of the web management interface. A patched firmware version (3.441b260626 or later) is available from PLANET.
Affected products
- PLANET GS-4210-16P2S V3 before 3.441b260626
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Patched firmware version 3.441b260626 available