Impact
The vulnerability allows an authenticated attacker to send crafted POST requests to /cgi-bin/dispatcher.cgi that copy the radKey, radKey_0, radDftParamKey, radName, and radIp parameters into fixed-size stack buffers without length validation and dereference radName and radIp without ensuring they are present. These actions trigger a stack buffer overflow and a null pointer dereference, causing the CGI process or web management service to crash. Because the flaw requires valid credentials before exploitation, the denial of service can disrupt network traffic management until the device is restarted.
Affected Systems
PLANET Technology Corp.'s GS-4210-16P2S network appliance running firmware versions prior to 3.441b260626 is affected. No other vendor or product is known to be impacted.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability has moderate severity. The EPSS score of 0.00433 (0.43%) indicates a very low exploitation probability, and the flaw is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Attackers need valid credentials and access to the web interface; once authenticated, they can send crafted requests to trigger a crash, resulting in a DoS.
OpenCVE Enrichment