Impact
An embedded debug function in PLANET IGS-5225-8P2T4S V1 and V2 firmware allows an attacker with privileged device access to enable debug mode and execute arbitrary code at the operating system level, resulting in root-level compromise. This flaw is a form of insecure debug functionality, classified as CWE‑489.
Affected Systems
PLANET Technology Corp models PLANET IGS-5225-8P2T4S V1 and V2 running firmware versions earlier than 1.2412b260707 or 2.2412b260519, respectively, are vulnerable.
Risk and Exploitability
The CVSS score is 8.4, indicating a high severity. The EPSS score of 0.125% (equivalent to 0.00125) suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV. Exploit requires privileged device access; the likely attack vector is through a local administrator or an attacker who has authenticated remote access to the management interface. Once enabled, the debug mode permits execution of arbitrary code, enabling a complete takeover of the device.
OpenCVE Enrichment