Memory Corruption Vulnerability in PLANET GS-4210-16P2S Firmware
CVE-2026-75124
8.7HIGH
Key Information:
- Vendor
Planet Technology Corp.
- Status
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-75124?
The firmware of the PLANET GS-4210-16P2S device is susceptible to a memory corruption vulnerability found in its web management interface. Specifically, the _readHttpParam function fails to ensure proper NUL termination when handling oversized HTTP query strings. An attacker can exploit this flaw by sending a specially crafted GET request to the dispatcher.cgi endpoint, which may lead to denial of service or the execution of malicious payloads. It is crucial for users to update their firmware to the latest version to mitigate this risk.
Affected Version(s)
PLANET GS-4210-16P2S V3 0 < 3.441b260626
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt)
Professor Le Yu of Nanjing University of Posts and Telecommunications
Professor Xiapu Luo of The Hong Kong Polytechnic University
