以下是对该漏洞描述信息的中文翻译: PLANET GS-4210-16P2S 固件版本 3.441b260626 之前的版本中, 存在经过身份验证的栈缓冲区溢出和空指针引用漏洞。 系列处理函数在未进行长度校验的情况下,将 POST 请求中的 、 、 、 和 参数直接复制到固定大小的栈缓冲区中;此外,在请求中未验证 和 是否存在的情况下,代码直接对它们进行了引用(解引用)。 经过身份验证的远程攻击者可以发送精心构造的请求,导致 CGI 进程或 Web 管理服务崩溃,从而造成拒绝服务(DoS)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | < 3.441b260626 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | 0 ~ 3.441b260626 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75124 | 7.5 HIGH | PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam |
| CVE-2026-75121 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_ |
| CVE-2026-75122 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi |
| CVE-2026-75123 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post |
| CVE-2026-75126 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers |
| CVE-2026-75125 | 4.9 MEDIUM | PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_p |
| CVE-2026-77218 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Credential Handlers |
No comments yet