CVE-2026-3697: Planet ICG-2510 Language Package Configuration httpd sub_40C8E4 stack-based overflow
A vulnerability was determined in Planet ICG-2510 1.020250811. The impacted element is the function sub40C8E4 of the file /usr/sbin/httpd of the component Language Package Configuration Handler. Executing a manipulation of the argument Language can lead to stack-based buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3697?
CVE-2026-3697 is rated as high severity due to the potential for stack-based overflow leading to remote code execution.
How do I fix CVE-2026-3697?
To fix CVE-2026-3697, update the Planet ICG-2510 firmware to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-3697?
The impacts of CVE-2026-3697 include possible remote exploitation, unauthorized access, and system compromise.
Which systems are affected by CVE-2026-3697?
CVE-2026-3697 specifically affects the Planet ICG-2510 version 1.0_20250811.
How can I mitigate risks associated with CVE-2026-3697?
To mitigate risks from CVE-2026-3697, ensure your devices are not exposed to untrusted networks and monitor for unusual activity.