Junglewise Threat Intelligence

CVE-2026-81945: PLANET IGS-5225-8P2T4S stack-based buffer overflow in web server

CVE-2026-81945 · Severity: medium · CVSS 6.6 · Published 2026-09-18

Technologies: PLANET IGS-5225-8P2T4S V2, PLANET IGS-5225-8P2T4S V1. Vendors: PLANET.

Executive brief

The PLANET IGS-5225-8P2T4S is an industrial managed network switch used to connect and protect devices in manufacturing and critical infrastructure environments. A stack-based buffer overflow in the device's web server allows a remote administrator to crash the switch or execute malicious code with system privileges, potentially leading to network outages or compromise of connected systems.

Technical details

A stack-based buffer overflow (CWE-121) exists in the web server due to insufficient bounds checking when copying data into a stack buffer. The vulnerability requires administrative credentials and network access, but permits remote code execution or denial of service on the underlying operating system. Patches are available: firmware v1.2412b260707 for V1 and v2.2412b260519 for V2.

Affected products

  • PLANET IGS-5225-8P2T4S V1 before 1.2412b260707
  • PLANET IGS-5225-8P2T4S V2 before 2.2412b260519

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Firmware v1.2412b260707 (V1) and v2.2412b260519 (V2) released

References

Related threats