SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75125

MEDIUM · CVSS 4.9 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The firmware of PLANET GS-4210-16P2S devices prior to version 3.441b260626 is vulnerable to an authenticated null pointer dereference in the web management interface, specifically within the /cgi-bin/dispatcher.cgi handler. This flaw allows a remote authenticated attacker to exploit the vulnerability by omitting the rmtIP parameter in a crafted request, leading to a denial of service condition that crashes the CGI process. Organizations using affected firmware should prioritize this vulnerability to prevent potential disruptions to their network management capabilities.

CVE
CVE-2026-75125
Severity
MEDIUM
CVSS
4.9
EPSS
0.39%

Original NVD Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.