CVE-2026-81946: PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch firmwareto a version that resolves this vulnerability.Fixed in 1.2412b260707 - Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch firmwareto a version that resolves this vulnerability.Fixed in 2.2412b260519 - Operational
If the device configuration file was obtained, assume the privileged-mode access password may have been recovered; change/rotate the privileged-mode access password after upgrading to the fixed firmware versions.
Event History
Frequently Asked Questions
What must an attacker obtain to exploit this issue?
The attacker must obtain the device configuration file. They can then recover the privileged-mode access password from the MD5-based password hash.
Which firmware versions are affected?
Affected releases are V1 firmware versions before 1.2412b260707 and V2 firmware versions before 2.2412b260519.
How can I determine whether a device needs remediation?
Check whether the switch is running V1 or V2 firmware, then compare its firmware version with the applicable fixed version. Devices running a version earlier than 1.2412b260707 for V1 or 2.2412b260519 for V2 are affected.