<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IGS-5225-8P2T4S (&lt; 1.2412b260707 and &lt; 2.2412b260519) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/igs-5225-8p2t4s--1.2412b260707-and--2.2412b260519/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 18:08:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/igs-5225-8p2t4s--1.2412b260707-and--2.2412b260519/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stack-based Buffer Overflow in PLANET IGS-5225-8P2T4S Managed Switches</title><link>https://feed.craftedsignal.io/briefs/2026-09-planet-igs-overflow/</link><pubDate>Fri, 18 Sep 2026 18:08:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-planet-igs-overflow/</guid><description>A stack-based buffer overflow vulnerability in the web server of PLANET IGS-5225-8P2T4S industrial managed switches allows authenticated remote attackers to achieve denial of service or remote code execution via CVE-2026-81944.</description><content:encoded><![CDATA[<p>PLANET IGS-5225-8P2T4S industrial managed switches (V1 and V2 firmware) contain a critical stack-based buffer overflow vulnerability identified as CVE-2026-81944. The flaw exists within the device's integrated web server, which fails to perform adequate bounds checking when copying user-supplied input into stack-based buffers. This vulnerability can be exploited by an authenticated remote attacker to overwrite memory, resulting in a denial-of-service condition or the potential for arbitrary code execution on the underlying operating system. The vulnerability affects firmware versions prior to 1.2412b260707 for V1 units and versions prior to 2.2412b260519 for V2 units. Given the deployment of these devices in industrial environments, successful exploitation could lead to significant operational disruption or unauthorized control over network infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an authenticated attacker to compromise the integrity and availability of industrial network switches. Impact includes device crashes (denial of service) or full remote code execution, which may permit persistent access to the network or the ability to manipulate traffic flowing through the industrial switch. Organizations in manufacturing, energy, and utility sectors utilizing these switches are at the highest risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade PLANET IGS-5225-8P2T4S (V1) firmware to version 1.2412b260707 or later.</li>
<li>Upgrade PLANET IGS-5225-8P2T4S (V2) firmware to version 2.2412b260519 or later.</li>
<li>Restrict access to the web management interface of industrial switches to trusted, hardened management workstations via VLAN segmentation and firewall rules.</li>
<li>Monitor for anomalous HTTP traffic directed at the web management interfaces of industrial networking equipment.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>industrial-control-systems</category><category>network-security</category><category>cve-2026-81944</category></item></channel></rss>