CVE-2026-75124: PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parsequerystring to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PLANET GS-4210-16P2Sto a version that resolves this vulnerability.Fixed in 3.441b260626 - Compensating control
Mitigate exposure by limiting access to the web management interface (e.g., restrict inbound access to dispatcher.cgi/web management endpoints to trusted IPs or via network ACL/WAF) until the firmware is upgraded.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker who can reach the device's web management interface can exploit it by sending an oversized GET request to dispatcher.cgi. No credentials or user interaction are required.
Which systems are affected?
PLANET GS-4210-16P2S devices running firmware before version 3.441b260626 are affected. The vulnerable component is the web management interface.
What is the practical impact of exploitation?
An attacker can cause denial of service of the web management interface. The memory corruption condition may also potentially allow further impact, but the provided information does not confirm code execution.
How can I determine whether my device is exposed?
Verify whether the device is a PLANET GS-4210-16P2S and check its installed firmware version. Devices running a version earlier than 3.441b260626 with a reachable web management interface should be treated as exposed.