Memory Corruption Vulnerability in PLANET GS-4210-16P2S Firmware
CVE-2026-75124

8.7HIGH

What is CVE-2026-75124?

The firmware of the PLANET GS-4210-16P2S device is susceptible to a memory corruption vulnerability found in its web management interface. Specifically, the _readHttpParam function fails to ensure proper NUL termination when handling oversized HTTP query strings. An attacker can exploit this flaw by sending a specially crafted GET request to the dispatcher.cgi endpoint, which may lead to denial of service or the execution of malicious payloads. It is crucial for users to update their firmware to the latest version to mitigate this risk.

Affected Version(s)

PLANET GS-4210-16P2S V3 0 < 3.441b260626

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt)
Professor Le Yu of Nanjing University of Posts and Telecommunications
Professor Xiapu Luo of The Hong Kong Polytechnic University
.