CVE-2026-75124
nichePre-authentication Memory Corruption in PLANET GS-4210-16P2S V3 Web Interface
CVE-2026-75124 is a pre-authentication memory corruption flaw (CWE-120) in the web management interface of PLANET GS-4210-16P2S V3 switches, where the _readHttpParam function copies an attacker-controlled HTTP query string without guaranteeing NUL termination. An unauthenticated remote attacker can trigger it by sending an oversized GET request to dispatcher.cgi, causing parse_query_string to process the unterminated data into a fixed-size stack buffer. The demonstrated impact is denial of service of the web management interface, with potential additional memory corruption; the CVSS 4.0 score of 8.7 (AV:N/VA:H with all other impact metrics None) reflects high availability impact only. Any organization running this switch model on V3 firmware prior to 3.441b260626 is affected, though the described impact is limited to the management interface rather than switch forwarding. No public PoC exists, the flaw is not in CISA KEV, and EPSS assigns a 0.5% (40th percentile) probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Upgrade GS-4210-16P2S V3 units to firmware 3.441b260626 or later. Until patched, restrict access to the web management interface (dispatcher.cgi) to trusted management networks via firewall/ACL rules and avoid exposing HTTP management to the internet. Inventory the network for this model and confirm which firmware revision each unit runs.
| PLANET GS-4210-16P2S V3 | firmware before 3.441b260626 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.
- Weakness
- CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.