---
id: CVE-2026-81943
title: >-
  PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions
  before 1.2412b260707 and 2.2412b260519 contain active debug functionality in
  the embedded software
summary: >-
  PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions
  before 1.2412b260707 and 2.2412b260519 contain active debug functionality in
  the embedded software. An attacker with privileged access to the device can
  enable …
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-489
vendor: PLANET Technology Corp.
product: PLANET IGS-5225-8P2T4S V1
affected:
  - planet_igs-5225-8p2t4s_v1 < 1.2412b260707
  - planet_igs-5225-8p2t4s_v2 < 2.2412b260519
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:43:58.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81943'
references:
  - url: 'https://www.planet.com.tw/en/support/security-advisory/11'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/planet-igs-5225-8p2t4s-v1-v2-debug-mode-rce
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00184
epssPercentile: 0.07117
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T15:40:36.637527Z'
ingestedAt: '2026-09-18T15:44:31.584Z'
---

## Overview

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable this debug mode to execute arbitrary code on the underlying operating system and gain root-level access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
