VYPR

Gs 4210 16p2s Firmware

by Planet

CVEs (8)

  • CVE-2026-75124HigAug 28, 2026
    risk 0.49cvss 7.5epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing…

  • CVE-2026-75123HigAug 28, 2026
    risk 0.47cvss 7.2epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote…

  • CVE-2026-75122HigAug 28, 2026
    risk 0.47cvss 7.2epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell…

  • CVE-2026-75121HigAug 28, 2026
    risk 0.47cvss 7.2epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A…

  • CVE-2026-77218MedAug 28, 2026
    risk 0.32cvss 4.9epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buffer without length validation, the…

  • CVE-2026-77217MedAug 28, 2026
    risk 0.32cvss 4.9epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radKey_0, radDftParamKey, radName, and radIp POST…

  • CVE-2026-75126MedAug 28, 2026
    risk 0.32cvss 4.9epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack buffers without length validation:…

  • CVE-2026-75125MedAug 28, 2026
    risk 0.32cvss 4.9epss

    PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker…