Planet · Gs-4210-16P2S V3 · CVE-2026-75126
**Name of the Vulnerable Software and Affected Versions**
PLANET GS-4210-16P2S V3 versions prior to 3.441b260626
**Description**
Multiple authenticated stack buffer overflow issues exist in the `/cgi-bin/dispatcher.cgi` endpoint. The vulnerability occurs when several handlers copy attacker-controlled POST parameters into fixed-size stack buffers without proper length validation. Affected handlers include `web vlan membership edit dialog post`, `web dai vlan post`, `web poe alive rmtip post`, `web sys sntp post`, `web tool upgradeManager post`, `web port countersClr post`, `web rmon statisticsClr post`, `web cablediag copper post`, `web aaa *Authlist*`, `web acl mgmt Rules Apply post`, `web acl mgmt Rules Edit post`, `web acl *AceDel post`, `web acl *AceAdd/Edit post`, `web acl bindAdd post`, `web acl bindEdit post`, `web snmp v3view add post`, `web snmp v3group add post`, `web snmp v3community add post`, `web snmp v3host add post`, `web snmp notifyv3 add post`, `web snmp v3user add post`, `web snmpv3 remote engineId add post`, `web stp globalSetting post`, `web isg db post`, `web tacplus* post`, `web dhcp option82 post`, and `web dhcp port option82 cid post`. A remote authenticated attacker can send crafted requests to crash the CGI process or web management service, leading to a denial of service.
**Recommendations**
Update to version 3.441b260626 or later.