Planet
Products
30- 15 CVEs
- 12 CVEs
- 12 CVEs
- 9 CVEs
- 9 CVEs
- 8 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
Recent CVEs
50| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-9972 | Cri | 0.64 | 9.8 | 0.02 | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device. | ||
| CVE-2025-9971 | Cri | 0.64 | 9.8 | 0.01 | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality. | ||
| CVE-2025-44898 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function. | ||
| CVE-2025-44897 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function. | ||
| CVE-2025-44896 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function. | ||
| CVE-2025-44894 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function. | ||
| CVE-2025-44891 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function. | ||
| CVE-2025-44883 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function. | ||
| CVE-2025-44893 | Cri | 0.64 | 9.8 | 0.01 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function. | ||
| CVE-2025-44890 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function. | ||
| CVE-2025-44888 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function. | ||
| CVE-2025-44887 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function. | ||
| CVE-2025-44886 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function. | ||
| CVE-2025-44885 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function. | ||
| CVE-2025-44884 | Cri | 0.64 | 9.8 | 0.00 | May 20, 2025 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function. | ||
| CVE-2024-48871 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2024 | The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before copying data to the stack, potentially allowing remote code execution. | ||
| CVE-2024-8456 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2024 | Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices. | ||
| CVE-2023-33553 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2023 | An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie. | ||
| CVE-2020-26097 | Cri | 0.64 | 9.8 | 0.02 | Nov 18, 2020 | The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no… | ||
| CVE-2025-54406 | Hig | 0.58 | 8.8 | 0.04 | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these… |
- risk 0.64cvss 9.8epss 0.02
Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.
- risk 0.64cvss 9.8epss 0.01
Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.
- risk 0.64cvss 9.8epss 0.01
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.
- risk 0.64cvss 9.8epss 0.00
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.
- risk 0.64cvss 9.8epss 0.01
The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before copying data to the stack, potentially allowing remote code execution.
- risk 0.64cvss 9.8epss 0.01
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.
- risk 0.64cvss 9.8epss 0.01
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.
- risk 0.64cvss 9.8epss 0.02
The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no…
- risk 0.58cvss 8.8epss 0.04
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these…