Impact
A stack‑based buffer overflow exists in the web server of the PLANET IGS‑5225‑8P2T4S switch firmware due to insufficient bounds checking on data copied into a stack buffer. A remote administrator can exploit the flaw by submitting crafted input, which may lead to a denial‑of‑service or, if the overflow is successfully leveraged, to execution of arbitrary code on the underlying operating system.
Affected Systems
The affected products are the PLANET IGS-5225-8P2T4S managed switch (V1 and V2). Vulnerable firmware versions are any V1 releases before 1.2412b260707 and any V2 releases before 2.2412b260519, as listed by the manufacturer’s advisory.
Risk and Exploitability
The CVSS base score is 7.5, indicating a high‑moderate level of risk. Exploit probability data from EPSS indicates a probability of less than 1%, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is a remote administrator accessing the device’s web interface; such a user can submit crafted input that triggers the overflow. The result could be service interruption or execution of malicious code, potentially giving the attacker complete control of the switch.
OpenCVE Enrichment