CyberRota Analysis
AI-GeneratedThe firmware of PLANET GS-4210-16P2S devices prior to version 3.441b260626 is vulnerable to an authenticated null pointer dereference in the web management interface, specifically within the /cgi-bin/dispatcher.cgi handler. This flaw allows a remote authenticated attacker to exploit the vulnerability by omitting the rmtIP parameter in a crafted request, leading to a denial of service condition that crashes the CGI process. Organizations using affected firmware should prioritize this vulnerability to prevent potential disruptions to their network management capabilities.
Original NVD Description
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.