Junglewise Threat Intelligence

CVE-2026-81944: PLANET IGS-5225-8P2T4S stack-based buffer overflow in web server

CVE-2026-81944 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: PLANET IGS-5225-8P2T4S V2, PLANET IGS-5225-8P2T4S V1. Vendors: PLANET.

Executive brief

The PLANET IGS-5225-8P2T4S is an industrial managed network switch used to provide secure connectivity in critical infrastructure environments. A stack-based buffer overflow in the device's web server allows an authenticated attacker to crash the device or execute arbitrary code with root privileges, potentially compromising the entire network segment the switch protects.

Technical details

A stack-based buffer overflow (CWE-121) exists in the web server component of affected firmware versions due to insufficient bounds checking when copying user-supplied data into a stack buffer. Remote authentication is required; the vulnerability is exploitable over the network with high complexity. Successful exploitation grants arbitrary code execution with operating system-level privileges, or can trigger denial of service.

Affected products

  • PLANET IGS-5225-8P2T4S V1 before 1.2412b260707
  • PLANET IGS-5225-8P2T4S V2 before 2.2412b260519

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Firmware v1.2412b260707 for V1 and v2.2412b260519 for V2

References

Related threats