CVE-2026-81946 PUBLISHED

PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm

Assigner: VulnCheck
Reserved: 27.08.2026 Published: 18.09.2026 Updated: 18.09.2026

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor PLANET Technology Corp.
Product PLANET IGS-5225-8P2T4S V1
Versions Default: unaffected
  • affected from 0 to 1.2412b260707 (excl.)
Vendor PLANET Technology Corp.
Product PLANET IGS-5225-8P2T4S V2
Versions Default: affected
  • affected from 0 to 2.2412b260519 (excl.)

Credits

  • Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (Positive Technologies) finder
  • Maksim Gruzin finder

References

Problem Types

  • Stack-based Buffer Overflow CWE