PatchSiren cyber security CVE debrief
CVE-2026-75124 PLANET Technology Corp. CVE debrief
The CVE-2026-75124 vulnerability affects PLANET GS-4210-16P2S V3 devices with firmware before 3.441b260626. This pre-authentication memory corruption vulnerability in the web management interface can be exploited by an unauthenticated remote attacker sending an oversized GET request to dispatcher.cgi, potentially causing denial of service and memory corruption. Defenders should verify exposure and assess the web management interface for potential vulnerabilities. The CVE record was published on 2026-08-28T20:19:52.970Z.
- Vendor
- PLANET Technology Corp.
- Product
- PLANET GS-4210-16P2S V3
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for PLANET GS-4210-16P2S V3 devices with firmware before 3.441b260626 should assess exposure and verify the web management interface for potential memory corruption vulnerabilities.
Why it matters
Defenders should prioritize verifying exposure of PLANET GS-4210-16P2S V3 devices with firmware before 3.441b260626 and assessing the web management interface for potential memory corruption vulnerabilities, as an unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service and potentially trigger memory corruption.
- Denial of service of the web management interface
- Potential memory corruption requiring verification
- Need for compensating controls to limit access to the web management interface
- Verification of firmware version and patching priority
Technical summary
The _readHttpParam function in PLANET GS-4210-16P2S V3 firmware before 3.441b260626 copies an oversized HTTP query string without guaranteeing NUL termination. This allows parse_query_string to process attacker-controlled data into a fixed-size stack buffer, potentially leading to memory corruption. An unauthenticated remote attacker can exploit this by sending an oversized GET request to dispatcher.cgi, causing denial of service and potentially triggering memory corruption in the web management interface. Defenders should prioritize verifying exposure and assessing the web management interface for potential vulnerabilities.
Defensive priority
Defenders should prioritize verifying exposure of PLANET GS-4210-16P2S V3 devices with firmware before 3.441b260626 and assessing the web management interface for potential memory corruption vulnerabilities.
Recommended defensive actions
- Verify exposure of PLANET GS-4210-16P2S V3 devices with firmware before 3.441b260626
- Assess the web management interface for potential memory corruption vulnerabilities
- Implement compensating controls to limit access to the web management interface
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description indicates a pre-authentication memory corruption vulnerability in the web management interface of PLANET GS-4210-16P2S V3 firmware before 3.441b260626. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75124 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75124
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75124 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75124
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.planet.com.tw/en/support/security-advisory/10
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/planet-gs-4210-16p2s-memory-corruption-via-dispatcher-cgi-readhttpparam
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.