PLANET GS-4210-16P2S 固件版本低于 3.441b260626 的 Web 管理界面中存在一个预认证内存损坏漏洞。具体而言, 函数在复制过长的 HTTP 查询字符串时,未确保以 NUL 字符结尾,导致 函数将攻击者控制的数据处理到一个固定大小的栈缓冲区中。未经身份验证的远程攻击者可以通过向 发送一个过长的 GET 请求,从而造成 Web 管理界面的拒绝服务(DoS),并可能触发内存损坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | < 3.441b260626 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | 0 ~ 3.441b260626 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75121 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_ |
| CVE-2026-75122 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi |
| CVE-2026-75123 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post |
| CVE-2026-75126 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers |
| CVE-2026-75125 | 4.9 MEDIUM | PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_p |
| CVE-2026-77217 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi |
| CVE-2026-77218 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Credential Handlers |
No comments yet