Arbitrary Code Execution Risk in PLANET IGS-5225-8P2T4S Industrial Managed Switch
CVE-2026-81943
8.4HIGH
Key Information:
- Vendor
Planet Technology Corp.
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-81943?
The PLANET IGS-5225-8P2T4S industrial managed switch features an embedded debug functionality in its firmware for versions prior to 1.2412b260707 and 2.2412b260519. This vulnerability allows an attacker with privileged access to exploit the debug mode, enabling them to execute arbitrary code on the device's underlying operating system. Successful exploitation provides the attacker with root-level access, which can compromise the device's integrity and security. Users are strongly advised to apply the recommended patches from PLANET to mitigate this risk.
Affected Version(s)
PLANET IGS-5225-8P2T4S V1 0 < 1.2412b260707
PLANET IGS-5225-8P2T4S V2 0
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (Positive Technologies)
Maksim Gruzin
