Weak Password Hashing in PLANET IGS-5225-8P2T4S Industrial Managed Switch
CVE-2026-81946

6.7MEDIUM

What is CVE-2026-81946?

The PLANET IGS-5225-8P2T4S industrial managed switch suffers from a security issue due to its use of MD5 for password hashing in firmware versions prior to 1.2412b260707 for V1 and 2.2412b260519 for V2. This outdated cryptographic algorithm, known for its vulnerabilities, allows attackers to potentially recover privileged-mode access passwords if they obtain the device configuration file. Organizations using these firmware versions are advised to update to the latest versions to enhance security.

Affected Version(s)

PLANET IGS-5225-8P2T4S V1 0 < 1.2412b260707

PLANET IGS-5225-8P2T4S V2 0

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (Positive Technologies)
Maksim Gruzin
.