CVE-2026-81945: PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote administrator to cause a denial of service or potentially execute arbitrary code on the underlying operating system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch firmwareto a version that resolves this vulnerability.Fixed in 1.2412b260707 - Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch firmwareto a version that resolves this vulnerability.Fixed in 2.2412b260519
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to reach the switch web server remotely and have administrator privileges. The vulnerability is therefore most relevant where administrative web access is exposed to untrusted or broadly reachable networks.
Which firmware releases are affected?
Affected releases are V1 firmware before 1.2412b260707 and V2 firmware before 2.2412b260519.
What can happen if the vulnerability is exploited?
A remote administrator can cause a denial of service and may be able to execute arbitrary code on the underlying operating system.