PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75126 PLANET Technology Corp. CVE debrief

A remote authenticated attacker can send crafted requests to crash the CGI process or web management service of PLANET GS-4210-16P2S V3 firmware before 3.441b260626, resulting in denial of service. Multiple authenticated stack buffer overflow vulnerabilities exist in /cgi-bin/dispatcher.cgi due to lack of length validation for attacker-controlled POST parameters.

Vendor
PLANET Technology Corp.
Product
PLANET GS-4210-16P2S V3
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-09-08
Advisory published
2026-08-28
Advisory updated
2026-09-08

Who should care

Network administrators and security teams responsible for managing PLANET GS-4210-16P2S V3 devices should assess their exposure to these vulnerabilities and prioritize applying the vendor-provided security patch.

Why it matters

CVE-2026-75126 exposes PLANET GS-4210-16P2S V3 devices to authenticated denial-of-service attacks. Network administrators and security teams must verify exposure, prioritize patching, and monitor for suspicious activity.

  • Denial of service due to CGI process or web management service crashes
  • Potential for remote authenticated attackers to disrupt device operation
  • Need for verification of firmware versions and exposure
  • Priority for applying vendor-provided security patches

Technical summary

Multiple authenticated stack buffer overflow vulnerabilities exist in the /cgi-bin/dispatcher.cgi script of PLANET GS-4210-16P2S V3 firmware before version 3.441b260626. The vulnerabilities are caused by the lack of length validation for attacker-controlled POST parameters in various handlers, including web_vlan_membership_edit_dialog_post, web_dai_vlan_post, and web_poe_alive_rmtip_post, among others. A remote authenticated attacker can exploit these vulnerabilities by sending crafted requests to crash the CGI process or web management service, resulting in a denial of service.

Defensive priority

Defenders should prioritize verifying exposure of GS-4210-16P2S V3 devices running firmware versions before 3.441b260626 and applying the vendor-provided security patch.

Recommended defensive actions

  • Verify exposure of GS-4210-16P2S V3 devices running firmware versions before 3.441b260626
  • Apply the vendor-provided security patch
  • Monitor for suspicious requests to /cgi-bin/dispatcher.cgi
  • Restrict access to the web management service
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerabilities and affected firmware version. Vendor security advisories and researcher reports offer additional context. The vulnerabilities exist in PLANET GS-4210-16P2S V3 firmware before 3.441b260626. Evidence is limited to public sources; defenders should verify exposure and apply patches with caution.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75126 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75126

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75126 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75126

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.