Executive brief
PLANET GS-4210-16P2S V3 is a managed gigabit network switch used to control and monitor enterprise network infrastructure. The device's web management interface contains stack buffer overflow and null pointer dereference flaws in the RADIUS server configuration handlers that allow an authenticated administrator to crash the web service, disrupting management access and potentially allowing denial of service attacks against network operations.
Technical details
The vulnerability is a stack buffer overflow combined with null pointer dereference in the web_radiusSrv*_post handler family (cmd=7936, 7938, 7940) within /cgi-bin/dispatcher.cgi. The POST parameters radKey, radKey_0, radDftParamKey, radName, and radIp are copied into fixed-size stack buffers without length validation; additionally, radName and radIp are dereferenced without verifying their presence in the request, leading to potential crashes. The flaw requires authentication at the administrator privilege level and network reachability to the management interface. Exploitation allows an authenticated remote attacker to crash the CGI process or web management service, denying legitimate administrative access. Firmware version 3.441b260626 and later contain the patch.
Affected products
- PLANET GS-4210-16P2S V3 before 3.441b260626
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Firmware 3.441b260626 and later