Executive brief
The PLANET GS-4210-16P2S V3 is a managed network switch with web-based administration. Multiple web management handlers fail to validate the length of user-supplied configuration parameters, allowing an authenticated administrator to trigger stack buffer overflows. An attacker with valid admin credentials can crash the web management service, causing temporary unavailability of remote device administration and configuration.
Technical details
The vulnerability is a stack-based buffer overflow (CWE-121) affecting 30+ authenticated POST handlers in /cgi-bin/dispatcher.cgi. The affected handlers (web_vlan_membership_edit_dialog_post, web_snmp_v3view_add_post, web_dhcp_option82_post, and others) copy attacker-controlled POST parameters directly into fixed-size stack buffers without length validation. An authenticated attacker with administrator-level web-management privileges can send oversized POST parameters to overflow the stack, crash the CGI process, and disrupt the web management interface. The attack requires valid authentication credentials and network access to the web management port. Patched firmware version 3.441b260626 and later addresses this issue by implementing proper buffer length validation.
Affected products
- PLANET GS-4210-16P2S V3 before 3.441b260626
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Patched firmware version 3.441b260626 released