Executive brief
The PLANET IGS-5225-8P2T4S is an industrial managed network switch used in critical infrastructure and enterprise environments. An attacker with administrative privileges can enable hidden debug functionality in vulnerable firmware versions to execute arbitrary code and take complete control of the device, potentially compromising all network traffic passing through it.
Technical details
The vulnerability exploits active debug code embedded in the firmware that allows code execution when enabled by an authenticated high-privilege user (CWE-489). Attack vector is local; the attacker must have existing privileged administrative access to the device. Successful exploitation grants root-level operating system access on the switch. Patches are available in firmware versions 1.2412b260707 for V1 and 2.2412b260519 for V2.
Affected products
- PLANET IGS-5225-8P2T4S V1 before 1.2412b260707
- PLANET IGS-5225-8P2T4S V2 before 2.2412b260519
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched