{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oplanetigs-5225-8p2t4s_firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:planet:igs-5225-8p2t4s_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-81944"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IGS-5225-8P2T4S (\u003c 1.2412b260707 and \u003c 2.2412b260519)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","industrial-control-systems","network-security","cve-2026-81944"],"_cs_type":"advisory","_cs_vendors":["PLANET"],"content_html":"\u003cp\u003ePLANET IGS-5225-8P2T4S industrial managed switches (V1 and V2 firmware) contain a critical stack-based buffer overflow vulnerability identified as CVE-2026-81944. The flaw exists within the device's integrated web server, which fails to perform adequate bounds checking when copying user-supplied input into stack-based buffers. This vulnerability can be exploited by an authenticated remote attacker to overwrite memory, resulting in a denial-of-service condition or the potential for arbitrary code execution on the underlying operating system. The vulnerability affects firmware versions prior to 1.2412b260707 for V1 units and versions prior to 2.2412b260519 for V2 units. Given the deployment of these devices in industrial environments, successful exploitation could lead to significant operational disruption or unauthorized control over network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to compromise the integrity and availability of industrial network switches. Impact includes device crashes (denial of service) or full remote code execution, which may permit persistent access to the network or the ability to manipulate traffic flowing through the industrial switch. Organizations in manufacturing, energy, and utility sectors utilizing these switches are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade PLANET IGS-5225-8P2T4S (V1) firmware to version 1.2412b260707 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade PLANET IGS-5225-8P2T4S (V2) firmware to version 2.2412b260519 or later.\u003c/li\u003e\n\u003cli\u003eRestrict access to the web management interface of industrial switches to trusted, hardened management workstations via VLAN segmentation and firewall rules.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous HTTP traffic directed at the web management interfaces of industrial networking equipment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T18:08:30Z","date_published":"2026-09-18T18:08:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-planet-igs-overflow/","summary":"A stack-based buffer overflow vulnerability in the web server of PLANET IGS-5225-8P2T4S industrial managed switches allows authenticated remote attackers to achieve denial of service or remote code execution via CVE-2026-81944.","title":"Stack-based Buffer Overflow in PLANET IGS-5225-8P2T4S Managed Switches","url":"https://feed.craftedsignal.io/briefs/2026-09-planet-igs-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:planet:igs-5225-8p2t4s_firmware:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}