Arbitrary Code Execution Risk in PLANET IGS-5225-8P2T4S Industrial Managed Switch
CVE-2026-81943

8.4HIGH

What is CVE-2026-81943?

The PLANET IGS-5225-8P2T4S industrial managed switch features an embedded debug functionality in its firmware for versions prior to 1.2412b260707 and 2.2412b260519. This vulnerability allows an attacker with privileged access to exploit the debug mode, enabling them to execute arbitrary code on the device's underlying operating system. Successful exploitation provides the attacker with root-level access, which can compromise the device's integrity and security. Users are strongly advised to apply the recommended patches from PLANET to mitigate this risk.

Affected Version(s)

PLANET IGS-5225-8P2T4S V1 0 < 1.2412b260707

PLANET IGS-5225-8P2T4S V2 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (Positive Technologies)
Maksim Gruzin
.