Stack Buffer Overflow and Null Pointer Dereference Vulnerability in PLANET GS-4210-16P2S
CVE-2026-77217

6.9MEDIUM

What is CVE-2026-77217?

The PLANET GS-4210-16P2S firmware prior to version 3.441b260626 is susceptible to stack buffer overflow and null pointer dereference vulnerabilities. These issues exist within the /cgi-bin/dispatcher.cgi component, which handles various POST parameters without appropriate length validation. This oversight allows an authenticated remote attacker to craft specially designed requests that may crash the CGI process or disrupt the web management service, ultimately leading to a denial of service.

Affected Version(s)

PLANET GS-4210-16P2S V3 0 < 3.441b260626

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt)
Professor Le Yu of Nanjing University of Posts and Telecommunications
Professor Xiapu Luo of The Hong Kong Polytechnic University
.