CVE-2026-75125
Received Received - Intake

Authenticated Null Pointer Dereference in PLANET GS-4210-16P2S Firmware

Vulnerability report for CVE-2026-75125, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: VulnCheck

Description

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
planet gs-4210-16p2s to 3.441b260626 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75125 is an authenticated null pointer dereference vulnerability in PLANET GS-4210-16P2S firmware before version 3.441b260626. The flaw exists in the /cgi-bin/dispatcher.cgi component, specifically in the web_poe_alive_rmtip_post handler which dereferences the rmtIP parameter without verifying its presence. An authenticated remote attacker can exploit this by sending a crafted request that omits the rmtIP parameter, causing the CGI process to crash and resulting in denial of service for the web management interface.

Detection Guidance

To detect this vulnerability, check if your PLANET GS-4210-16P2S firmware version is prior to 3.441b260626. Use the web interface or CLI to verify the firmware version. If vulnerable, test by sending a crafted request omitting the rmtIP parameter to /cgi-bin/dispatcher.cgi and observe if the web management interface crashes.

Example command to check firmware version via CLI: show version. If the version is below 3.441b260626, the system is vulnerable.

Impact Analysis

This vulnerability allows an authenticated remote attacker to crash the web management interface of the affected device, causing a denial of service. This disrupts access to the device's management functions, potentially leading to loss of control or visibility over network operations.

Mitigation Strategies

Immediately update the PLANET GS-4210-16P2S firmware to version 3.441b260626 or later. Disable remote access to the web management interface if not required. Restrict authenticated user access to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75125. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart