Description
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password.
Published: 2026-09-18
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privileged Password Disclosure
Action: Apply Patch
AI Analysis

Impact

The firmware versions of PLANET IGS‑5225‑8P2T4S switches before 1.2412b260707 for V1 and 2.2412b260519 for V2 use MD5 to hash privileged‑mode passwords. MD5 is a broken hash algorithm that can be inverted with preimage attacks, enabling a malicious actor who obtains the configuration file to recover the password. This leads to exposure of privileged credentials and potential control over the switch.

Affected Systems

PLANET Technology Corp. PLANET IGS‑5225‑8P2T4S switches with V1 firmware earlier than 1.2412b260707 or V2 firmware earlier than 2.2412b260519 are affected. These industrial switches are often deployed in operational technology environments where configuration files may be accessed through physical media or remote management interfaces.

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity, and the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred: an attacker must obtain the device’s configuration file, which can occur through physical access, a compromised management session, or a fault in configuration management. If such access is achieved, the attacker can recover the privileged‑mode password and gain unauthorized control of the switch.

Generated by OpenCVE AI on September 19, 2026 at 20:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware from PLANET Technology Corp that replaces MD5 hashing with a stronger algorithm.
  • Limit physical and remote access to the device’s configuration file through strong authentication, restricted permissions, and, when possible, multi‑factor authentication.
  • Configure network segmentation and enable audit logging for configuration changes to reduce the exposure of configuration files and detect unauthorized activity.

Generated by OpenCVE AI on September 19, 2026 at 20:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Planet Technology Corp
Planet Technology Corp planet Igs-5225-8p2t4s V1
Planet Technology Corp planet Igs-5225-8p2t4s V2
Vendors & Products Planet Technology Corp
Planet Technology Corp planet Igs-5225-8p2t4s V1
Planet Technology Corp planet Igs-5225-8p2t4s V2

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password.
Title PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Planet Technology Corp Planet Igs-5225-8p2t4s V1 Planet Igs-5225-8p2t4s V2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:41:11.110Z

Reserved: 2026-08-27T20:41:13.616Z

Link: CVE-2026-81946

cve-icon Vulnrichment

Updated: 2026-09-22T14:41:04.315Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:11.560

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-81946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:12Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow