CVE-2026-81944: PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote authenticated attacker to cause a denial of service or potentially execute arbitrary code on the underlying operating system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch (web server)to a version that resolves this vulnerability.Fixed in 1.2412b260707 - Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch (web server)to a version that resolves this vulnerability.Fixed in 2.2412b260519
Event History
Frequently Asked Questions
Which deployments are affected?
PLANET IGS-5225-8P2T4S industrial managed switches running V1 firmware before 1.2412b260707 or V2 firmware before 2.2412b260519 are affected.
What access does an attacker need?
An attacker must be able to reach the switch web server over the network and authenticate with an account. No user interaction is required.
What could exploitation achieve?
Successful exploitation can cause a denial of service and may allow arbitrary code execution on the switch's underlying operating system.