PLANET GS-4210-16P2S 固件版本低于 3.441b260626 的 /cgi-bin/dispatcher.cgi 存在认证后栈缓冲区溢出漏洞。 具体而言: web_login_first_post 处理器在将 POST 参数 usrPass 复制到固定大小的栈缓冲区时,未进行长度校验; web_sys_enablePasswd_post 处理器在将 POST 参数 enbPass 复制到固定大小的栈缓冲区时,未进行长度校验; web_sys_localUser_post 处理器在将 POST 参
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | < 3.441b260626 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | 0 ~ 3.441b260626 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75124 | 7.5 HIGH | PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam |
| CVE-2026-75121 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_ |
| CVE-2026-75122 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi |
| CVE-2026-75123 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post |
| CVE-2026-75126 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers |
| CVE-2026-75125 | 4.9 MEDIUM | PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_p |
| CVE-2026-77217 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi |
No comments yet