CVE-2026-75125

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the rmtIP parameter to cause the CGI process to dereference a null pointer and crash, resulting in denial of service of the web management interface.

  • Published Aug 28, 2026
  • CVSS 6.9 medium
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-75125 at the National Vulnerability Database