CVE-2026-81943
8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable this debug mode to execute arbitrary code on the underlying operating system and gain root-level access.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V1 | 0 < 1.2412b260707 | affected |
| PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V2 | 0 < 2.2412b260519 | affected |
Weaknesses
- CWE-489: Active Debug Code
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.planet.com.tw/en/support/security-advisory/11
- https://www.vulncheck.com/advisories/planet-igs-5225-8p2t4s-v1-v2-debug-mode-rce
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.