VYPR

Vendor CVEs

Planet

All CVEs

72 total · sorted by risk
  • CVE-2026-81945MedSep 18, 2026
    risk 0.43cvss 6.6epss 0.00

    PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote administrator to cause a…

  • CVE-2025-44895MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

  • CVE-2025-44892MedMay 21, 2025
    risk 0.42cvss 6.5epss 0.00

    FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

  • CVE-2024-2742MedApr 11, 2024
    risk 0.42cvss 6.4epss 0.01

    Operating system command injection vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. An authenticated attacker could execute arbitrary code on the remote host by exploiting IP address functionality.

  • CVE-2022-45895MedDec 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

  • CVE-2022-45894MedDec 25, 2022
    risk 0.42cvss 6.5epss 0.01

    GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.

  • CVE-2026-3697MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in Planet ICG-2510 1.0_20250811. The impacted element is the function sub_40C8E4 of the file /usr/sbin/httpd of the component Language Package Configuration Handler. Executing a manipulation of the argument Language can lead to stack-based buffer…

  • CVE-2022-45890MedDec 25, 2022
    risk 0.40cvss 6.1epss 0.00

    In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).

  • CVE-2022-45892MedDec 25, 2022
    risk 0.35cvss 5.4epss 0.00

    In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.

  • CVE-2024-52558MedDec 6, 2024
    risk 0.34cvss 5.3epss 0.01

    The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP request, which could allow the attacker to crash the program.

  • CVE-2024-8454MedSep 30, 2024
    risk 0.34cvss 5.3epss 0.01

    The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.

  • CVE-2026-77218MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.00

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buffer without length validation, the…

  • CVE-2026-77217MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.00

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radKey_0, radDftParamKey, radName, and radIp…

  • CVE-2026-75126MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.00

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack buffers without length validation:…

  • CVE-2026-75125MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.00

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker…

  • CVE-2024-8453MedSep 30, 2024
    risk 0.32cvss 4.9epss 0.00

    Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext…

  • CVE-2024-8457MedSep 30, 2024
    risk 0.31cvss 4.8epss 0.00

    Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

  • CVE-2026-81946MedSep 18, 2026
    risk 0.29cvss 4.4epss 0.00

    PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the…

  • CVE-2023-32303MedMay 12, 2023
    risk 0.27cvss 5.2epss 0.00

    Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This…

  • CVE-2007-4477Aug 22, 2007
    risk 0.00cvss —epss 0.02

    The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

  • CVE-2005-3196Oct 14, 2005
    risk 0.00cvss —epss 0.00

    Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.

  • CVE-2003-1507Dec 31, 2003
    risk 0.00cvss —epss 0.02

    Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.

Page 2 of 2