Impact
The firmware on PLANET GS‑4210‑16P2S devices before version 3.441b260626 contains an authenticated null pointer dereference in the dispatcher.cgi utility. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence; a remote authenticated attacker can craft a request omitting this parameter to trigger a null pointer dereference, causing the CGI process to crash and resulting in denial of service of the web management interface. This impact is limited to interruption of the device’s web management services, with no code execution or data exposure.
Affected Systems
PLANET Technology Corp. devices branded GS‑4210‑16P2S running firmware versions prior to 3.441b260626 are affected. The vulnerability is only present in the web management software bundled with these releases.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high severity. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability requires the attacker to be authenticated to the web interface, further reducing the likelihood of widespread exploitation. Because it is not listed in the CISA KEV catalog, it is presently not a known exploited vulnerability. An attacker who can authenticate can repeatedly trigger the crash, resulting in sustained denial of service of the device's web management component and possible network‑management disruptions.
OpenCVE Enrichment