Description
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.
Published: 2026-08-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The firmware on PLANET GS‑4210‑16P2S devices before version 3.441b260626 contains an authenticated null pointer dereference in the dispatcher.cgi utility. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence; a remote authenticated attacker can craft a request omitting this parameter to trigger a null pointer dereference, causing the CGI process to crash and resulting in denial of service of the web management interface. This impact is limited to interruption of the device’s web management services, with no code execution or data exposure.

Affected Systems

PLANET Technology Corp. devices branded GS‑4210‑16P2S running firmware versions prior to 3.441b260626 are affected. The vulnerability is only present in the web management software bundled with these releases.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium‑to‑high severity. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability requires the attacker to be authenticated to the web interface, further reducing the likelihood of widespread exploitation. Because it is not listed in the CISA KEV catalog, it is presently not a known exploited vulnerability. An attacker who can authenticate can repeatedly trigger the crash, resulting in sustained denial of service of the device's web management component and possible network‑management disruptions.

Generated by OpenCVE AI on September 2, 2026 at 04:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to version 3.441b260626 or later to eliminate the null pointer dereference.
  • Limit access to the web management interface to a trusted network segment or disable it if remote management is not required, thereby reducing the attack surface.
  • Monitor the web interface for repeated CGI crashes and configure alerts; consider implementing input validation for the rmtIP parameter if the firmware allows configuration changes.

Generated by OpenCVE AI on September 2, 2026 at 04:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface. PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.
Title PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_post PLANET GS-4210-16P2S V3 Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_post

Mon, 31 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Planet Technology Corp
Planet Technology Corp planet Gs-4210-16p2s
Vendors & Products Planet Technology Corp
Planet Technology Corp planet Gs-4210-16p2s

Fri, 28 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.
Title PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_post
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Planet Technology Corp Planet Gs-4210-16p2s
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-01T20:28:07.967Z

Reserved: 2026-08-17T18:39:57.660Z

Link: CVE-2026-75125

cve-icon Vulnrichment

Updated: 2026-08-28T20:26:43.288Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-28T20:19:53.103

Modified: 2026-09-08T20:20:22.260

Link: CVE-2026-75125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:00:13Z

Weaknesses