Executive brief
The PLANET IGS-5225-8P2T4S industrial managed switch uses MD5-based password hashing in its firmware, a cryptographic method that can be cracked quickly by attackers. If an attacker gains access to the device configuration file, they can recover the privileged administrator password and compromise the switch controlling industrial network traffic. This affects both V1 and V2 hardware versions running older firmware.
Technical details
CVE-2026-81946 involves use of HMAC-MD5 for password hashing in the switch firmware, which is vulnerable to brute-force attacks due to MD5's cryptographic weaknesses. An attacker with access to the device configuration file (requiring local or prior network access to extract it) can recover the privileged-mode password through offline cracking. The vendor has patched this by replacing HMAC-MD5 with HMAC-SHA-256 in firmware versions 1.2412b260707 (V1) and 2.2412b260519 (V2).
Affected products
- PLANET IGS-5225-8P2T4S V1 firmware before 1.2412b260707
- PLANET IGS-5225-8P2T4S V2 firmware before 2.2412b260519
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Firmware 1.2412b260707 (V1) and 2.2412b260519 (V2)