Impact
The vulnerability allows an authenticated attacker to craft POST requests to /cgi-bin/dispatcher.cgi that overflow fixed‑size stack buffers and dereference null pointers, causing the process to crash and the web management service to fail. Because the flaw is limited to authenticated access, an attacker must have valid credentials to the device before exploitation. The resulting denial of service can halt network traffic management until the device is restarted.
Affected Systems
PLANET Technology Corp.'s GS-4210-16P2S network appliance running firmware versions prior to 3.441b260626 is affected. No other vendor or product is known to be impacted.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability has moderate severity. The EPSS score is not available and the flaw is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Attackers need valid credentials and access to the web interface; once authenticated, they can send crafted requests to trigger a crash, resulting in a DoS.
OpenCVE Enrichment