Impact
The vulnerability is a stack‑based buffer overflow in the web server of the PLANET IGS-5225-8P2T4S industrial managed switches. Insufficient bounds checking when copying data into a stack buffer allows an attacker that has authenticated to the web interface to send malformed requests. The flaw can lead to denial of service or, in the worst case, execution of arbitrary code on the underlying operating system.
Affected Systems
PLANET Technology Corp. products PLANET IGS-5225-8P2T4S V1 and V2. Firmware revisions prior to 1.2412b260707 for the V1 line and prior to 2.2412b260519 for the V2 line are affected. Updated releases beyond those revisions contain the fix.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS rating is <1% and it is not listed in the CISA KEV catalog, suggesting a very low current exploitation probability. Because authentication is required, a remote attacker must first obtain valid credentials to the web interface. Once authenticated, an attacker can craft a payload that triggers the stack-based buffer overflow, potentially leading to arbitrary code execution. The high CVSS score and the possibility of RCE warrant strong mitigation measures despite the low EPSS.
OpenCVE Enrichment