Security Advisory

CVE-2026-75124

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-28 15:32:13
Last updated 2026-09-01 20:27:50
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.