PatchSiren

PLANET Technology Corp. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-77218

A remote authenticated attacker can exploit authenticated stack buffer overflow vulnerabilities in PLANET GS-4210-16P2S V3 firmware before 3.441b260626, potentially causing denial of service. The vulnerabilities are located in /cgi-bin/dispatcher.cgi and involve the web_login_first_post, web_sys_enablePasswd_post, and web_sys_localUser_post handlers. These handlers copy POST parameters into fixed-size sta [truncated]

MEDIUM PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-77217

CVE-2026-77217 is a medium-severity vulnerability in PLANET GS-4210-16P2S V3 firmware before version 3.441b260626. The vulnerability is caused by authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. A remote authenticated attacker can send crafted requests to crash the CGI process or web management service, resulting in denial of service.

MEDIUM PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-75126

A remote authenticated attacker can send crafted requests to crash the CGI process or web management service of PLANET GS-4210-16P2S V3 firmware before 3.441b260626, resulting in denial of service. Multiple authenticated stack buffer overflow vulnerabilities exist in /cgi-bin/dispatcher.cgi due to lack of length validation for attacker-controlled POST parameters.

MEDIUM PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-75125

A vulnerability in PLANET GS-4210-16P2S V3 firmware before version 3.441b260626 allows an authenticated attacker to cause a denial of service (DoS) condition in the web management interface. The vulnerability is due to an authenticated null pointer dereference in the /cgi-bin/dispatcher.cgi file, specifically in the web_poe_alive_rmtip_post handler. This handler dereferences the rmtIP parameter without ve [truncated]

HIGH PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-75124

The CVE-2026-75124 vulnerability affects PLANET GS-4210-16P2S V3 devices with firmware before 3.441b260626. This pre-authentication memory corruption vulnerability in the web management interface can be exploited by an unauthenticated remote attacker sending an oversized GET request to dispatcher.cgi, potentially causing denial of service and memory corruption. Defenders should verify exposure and assess [truncated]

HIGH PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-75123

CVE-2026-75123 is an authenticated OS command injection vulnerability in PLANET GS-4210-16P2S V3 firmware before 3.441b260626. The vulnerability exists in the /cgi-bin/dispatcher.cgi file, specifically in the web_smtp_test_post handler, which incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web credentials can send a [truncated]

HIGH PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-75122

CVE-2026-75122 is an authenticated OS command injection vulnerability in PLANET GS-4210-16P2S V3 firmware before 3.441b260626. The vulnerability exists in the /cgi-bin/httpuploadcert.cgi script, where the certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can subm [truncated]

HIGH PLANET Technology Corp. CVE published 2026-08-28

CVE-2026-75121

CVE-2026-75121 is an authenticated OS command injection vulnerability in PLANET GS-4210-16P2S V3 firmware before 3.441b260626. The vulnerability exists in the /cgi-bin/dispatcher.cgi file, specifically in the web_vlan_membership_edit_dialog_post handler, which incorporates the memberTags POST parameter into a shell command without sanitization. This allows a remote authenticated attacker to execute arbitr [truncated]