Executive brief
The PLANET GS-4210-16P2S V3 is a managed network switch with a built-in web management interface. The firmware contains authenticated stack buffer overflow vulnerabilities in credential-handling functions that allow an authenticated attacker to crash the web management service, resulting in a denial of service and preventing legitimate administrators from managing the device.
Technical details
Stack-based buffer overflow vulnerabilities (CWE-121) exist in three authenticated handlers within /cgi-bin/dispatcher.cgi: web_login_first_post (usrPass parameter), web_sys_enablePasswd_post (enbPass parameter), and web_sys_localUser_post (usrName and usrPass parameters). Each handler copies POST parameters into fixed-size stack buffers without length validation, allowing oversized input to overflow. Attack requires prior authentication to the web management interface. Successful exploitation causes the CGI process or web management service to crash, resulting in denial of service. Patched firmware version 3.441b260626 and later address the vulnerability.
Affected products
- PLANET GS-4210-16P2S V3 before 3.441b260626
Timeline
- 2026-08-28: disclosed