PT-2026-83272 · Planet · Gs-4210-16P2S V3

·

CVE-2026-75126

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PLANET GS-4210-16P2S V3 versions prior to 3.441b260626
Description Multiple authenticated stack buffer overflow issues exist in the /cgi-bin/dispatcher.cgi endpoint. The vulnerability occurs when several handlers copy attacker-controlled POST parameters into fixed-size stack buffers without proper length validation. Affected handlers include web vlan membership edit dialog post, web dai vlan post, web poe alive rmtip post, web sys sntp post, web tool upgradeManager post, web port countersClr post, web rmon statisticsClr post, web cablediag copper post, web aaa *Authlist*, web acl mgmt Rules Apply post, web acl mgmt Rules Edit post, web acl *AceDel post, web acl *AceAdd/Edit post, web acl bindAdd post, web acl bindEdit post, web snmp v3view add post, web snmp v3group add post, web snmp v3community add post, web snmp v3host add post, web snmp notifyv3 add post, web snmp v3user add post, web snmpv3 remote engineId add post, web stp globalSetting post, web isg db post, web tacplus* post, web dhcp option82 post, and web dhcp port option82 cid post. A remote authenticated attacker can send crafted requests to crash the CGI process or web management service, leading to a denial of service.
Recommendations Update to version 3.441b260626 or later.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75126

Affected Products

Gs-4210-16P2S V3