Junglewise Threat Intelligence

CVE-2026-81943: PLANET IGS-5225-8P2T4S debug mode remote code execution

CVE-2026-81943 · Severity: medium · CVSS 6.7 · Published 2026-09-18

Technologies: PLANET IGS-5225-8P2T4S V2, PLANET IGS-5225-8P2T4S V1. Vendors: PLANET.

Executive brief

The PLANET IGS-5225-8P2T4S is an industrial managed network switch used in critical infrastructure and enterprise environments. An attacker with administrative privileges can enable hidden debug functionality in vulnerable firmware versions to execute arbitrary code and take complete control of the device, potentially compromising all network traffic passing through it.

Technical details

The vulnerability exploits active debug code embedded in the firmware that allows code execution when enabled by an authenticated high-privilege user (CWE-489). Attack vector is local; the attacker must have existing privileged administrative access to the device. Successful exploitation grants root-level operating system access on the switch. Patches are available in firmware versions 1.2412b260707 for V1 and 2.2412b260519 for V2.

Affected products

  • PLANET IGS-5225-8P2T4S V1 before 1.2412b260707
  • PLANET IGS-5225-8P2T4S V2 before 2.2412b260519

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched

References

Related threats