VYPR

Vendor CVEs

Planet

All CVEs

50 total · sorted by risk
  • CVE-2025-9972CriSep 17, 2025
    risk 0.64cvss 9.8epss 0.02

    Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2025-9971CriSep 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality.

  • CVE-2025-44898CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

  • CVE-2025-44897CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.

  • CVE-2025-44896CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.

  • CVE-2025-44894CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.

  • CVE-2025-44891CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

  • CVE-2025-44883CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.

  • CVE-2025-44893CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.01

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

  • CVE-2025-44890CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.

  • CVE-2025-44888CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.

  • CVE-2025-44887CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

  • CVE-2025-44886CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.

  • CVE-2025-44885CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

  • CVE-2025-44884CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

  • CVE-2024-48871CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before copying data to the stack, potentially allowing remote code execution.

  • CVE-2024-8456CriSep 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.

  • CVE-2023-33553CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.

  • CVE-2020-26097CriNov 18, 2020
    risk 0.64cvss 9.8epss 0.02

    The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no…

  • CVE-2025-54406HigOct 7, 2025
    risk 0.58cvss 8.8epss 0.04

    Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2025-54405HigOct 7, 2025
    risk 0.58cvss 8.8epss 0.04

    Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2025-48826HigOct 7, 2025
    risk 0.58cvss 8.8epss 0.04

    A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to memory corruption. An attacker can send a series of HTTP requests to trigger this vulnerability.

  • CVE-2025-54404HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.04

    Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command…

  • CVE-2025-54403HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.04

    Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command…

  • CVE-2025-54402HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2025-54401HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2025-54400HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2025-54399HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.01

    Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these…

  • CVE-2024-8458HigSep 30, 2024
    risk 0.57cvss 8.8epss 0.00

    Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions…

  • CVE-2024-8448HigSep 30, 2024
    risk 0.57cvss 8.8epss 0.00

    Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell.

  • CVE-2024-8450HigSep 30, 2024
    risk 0.56cvss 8.6epss 0.00

    Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges.

  • CVE-2024-8455HigSep 30, 2024
    risk 0.53cvss 8.1epss 0.00

    The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who…

  • CVE-2024-2740HigApr 11, 2024
    risk 0.50cvss 7.7epss 0.00

    Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface.

  • CVE-2024-8452HigSep 30, 2024
    risk 0.49cvss 7.5epss 0.00

    Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.

  • CVE-2024-8451HigSep 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the…

  • CVE-2024-8459HigSep 30, 2024
    risk 0.47cvss 7.2epss 0.00

    Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.

  • CVE-2024-2741HigApr 11, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to trick some authenticated users into performing actions in their session, such as adding or updating accounts…

  • CVE-2024-8449MedSep 30, 2024
    risk 0.44cvss 6.8epss 0.00

    Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

  • CVE-2025-44895MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

  • CVE-2025-44892MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

  • CVE-2024-2742MedApr 11, 2024
    risk 0.42cvss 6.4epss 0.01

    Operating system command injection vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. An authenticated attacker could execute arbitrary code on the remote host by exploiting IP address functionality.

  • CVE-2026-3697MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in Planet ICG-2510 1.0_20250811. The impacted element is the function sub_40C8E4 of the file /usr/sbin/httpd of the component Language Package Configuration Handler. Executing a manipulation of the argument Language can lead to stack-based buffer…

  • CVE-2024-52558MedDec 6, 2024
    risk 0.34cvss 5.3epss 0.01

    The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP request, which could allow the attacker to crash the program.

  • CVE-2024-8454MedSep 30, 2024
    risk 0.34cvss 5.3epss 0.01

    The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.

  • CVE-2024-8453MedSep 30, 2024
    risk 0.32cvss 4.9epss 0.00

    Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext…

  • CVE-2024-8457MedSep 30, 2024
    risk 0.31cvss 4.8epss 0.00

    Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

  • CVE-2023-32303MedMay 12, 2023
    risk 0.27cvss 5.2epss 0.00

    Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This…

  • CVE-2007-4477Aug 22, 2007
    risk 0.00cvss epss 0.02

    The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

  • CVE-2005-3196Oct 14, 2005
    risk 0.00cvss epss 0.00

    Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.

  • CVE-2003-1507Dec 31, 2003
    risk 0.00cvss epss 0.02

    Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.