CVE-2026-81942 (OS Command Injection via Web Server / CWE-78):
PLANET IGS-5225-8P2T4S V1 and V2 firmware versions prior to v1.2412b260707 and v2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root. CVSS v4.0: 8.7 (High), CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. CVSS v3.1: 8.8 (High), CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
CVE-2026-81943 (Debug Mode RCE / CWE-489):
PLANET IGS-5225-8P2T4S V1 and V2 firmware versions prior to v1.2412b260707 and v2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable this debug mode to execute arbitrary code on the underlying operating system and gain root-level access. CVSS v4.0: 8.4 (High), CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. CVSS v3.1: 6.7 (Medium), CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H.
CVE-2026-81944 (Stack-Based Buffer Overflow via Web Server / CWE-121):
PLANET IGS-5225-8P2T4S V1 and V2 firmware versions prior to v1.2412b260707 and v2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote authenticated attacker to cause a denial of service or potentially execute arbitrary code on the underlying operating system. CVSS v4.0: 7.7 (High), CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. CVSS v3.1: 7.5 (High), CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.
CVE-2026-81945 (Admin Stack-Based Buffer Overflow via Web Server / CWE-121):
PLANET IGS-5225-8P2T4S V1 and V2 firmware versions prior to v1.2412b260707 and v2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote administrator to cause a denial of service or potentially execute arbitrary code on the underlying operating system. CVSS v4.0: 7.5 (High), CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. CVSS v3.1: 6.6 (Medium), CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H.
CVE-2026-81946 (Weak Password Hashing via MD5 Algorithm):
PLANET IGS-5225-8P2T4S V1 and V2 firmware versions prior to v1.2412b260707 and v2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password. The fixed firmware replaces the affected HMAC-MD5 mechanism with HMAC-SHA-256. CVSS v4.0: 6.7 (Medium), CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. CVSS v3.1: 4.4 (Medium), CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N.
| Product Series | Affected Version | Patch Availability |
| IGS-5225-8P2T4S V1 | Versions prior to v1.2412b260707 (v1.440b210519 confirmed affected) | v1.2412b260707 |
| IGS-5225-8P2T4S V2 | Versions prior to v2.2412b260519 (v2.2412b260203 confirmed affected) | v2.2412b260519 |
[2026-09-18]: Initial Version