Planet records
39 published records for vendor planet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 2.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-121 Stack-based Buffer Overflow19
- CWE-798 Use of Hard-coded Credentials4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-287 Improper Authentication1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-26097No exploit | The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet.planet · nvr-915 firmware · CWE-798 | Critical9.8 | — | 1.8% | Nov 18, 2020 |
39Monitor | CVE-2023-33553No exploit | An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulplanet · wdrt-1800ax firmware · CWE-287 | Critical9.8 | — | 1.0% | Jun 7, 2023 |
39Monitor | CVE-2025-44893No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post fuplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.7% | May 20, 2025 |
39Monitor | CVE-2024-8456No exploit | PLANET Technology switch devices - Missing Authentication for multiple HTTP routesplanet · gs-4210-24p2s firmware · CWE-306 | Critical9.8 | — | 0.6% | Sep 30, 2024 |
39Monitor | CVE-2025-44887No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.planet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44883No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.planet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44884No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.planet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44885No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_posplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44886No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44888No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post funplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44890No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.planet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44891No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.planet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44894No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post fplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44896No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post functiplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44897No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post fuplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2025-44898No exploit | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit functiplanet · wgs-804hpt firmware · CWE-121 | Critical9.8 | — | 0.5% | May 20, 2025 |
39Monitor | CVE-2024-8450No exploit | PLANET Technology switch devices - Hard-coded SNMPv1 read-write community stringplanet · gs-4210-24p2s firmware · CWE-798 | Critical9.8 | — | 0.4% | Sep 30, 2024 |
37Monitor | CVE-2025-48826No exploit | A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-134 | High8.8 | — | 6.9% | Oct 7, 2025 |
36Monitor | CVE-2025-54403No exploit | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-78 | High8.8 | — | 4.6% | Oct 7, 2025 |
36Monitor | CVE-2025-54404No exploit | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-78 | High8.8 | — | 4.6% | Oct 7, 2025 |
36Monitor | CVE-2025-54405No exploit | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-78 | High8.8 | — | 4.3% | Oct 7, 2025 |
36Monitor | CVE-2025-54406No exploit | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-78 | High8.8 | — | 4.3% | Oct 7, 2025 |
35Monitor | CVE-2025-54399No exploit | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-121 | High8.8 | — | 0.8% | Oct 7, 2025 |
35Monitor | CVE-2025-54402No exploit | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-121 | High8.8 | — | 0.8% | Oct 7, 2025 |
35Monitor | CVE-2025-54401No exploit | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.planet · wgr-500 firmware · CWE-121 | High8.8 | — | 0.7% | Oct 7, 2025 |
- CVE-2020-2609740Plan
The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet.
CriticalCVSS 9.8No exploitEPSS 2%planet · nvr-915 firmwareNov 18, 2020
- CVE-2023-3355339Monitor
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipul
CriticalCVSS 9.8No exploitEPSS 1%planet · wdrt-1800ax firmwareJun 7, 2023
- CVE-2025-4489339Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post fu
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2024-845639Monitor
PLANET Technology switch devices - Missing Authentication for multiple HTTP routes
CriticalCVSS 9.8No exploitEPSS 1%planet · gs-4210-24p2s firmwareSep 30, 2024
- CVE-2025-4488739Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4488339Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4488439Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4488539Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_pos
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4488639Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postc
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4488839Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post fun
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4489039Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4489139Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4489439Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post f
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4489639Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post functi
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4489739Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post fu
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2025-4489839Monitor
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit functi
CriticalCVSS 9.8No exploitEPSS 1%planet · wgs-804hpt firmwareMay 20, 2025
- CVE-2024-845039Monitor
PLANET Technology switch devices - Hard-coded SNMPv1 read-write community string
CriticalCVSS 9.8No exploitEPSS 0%planet · gs-4210-24p2s firmwareSep 30, 2024
- CVE-2025-4882637Monitor
A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 7%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5440336Monitor
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 5%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5440436Monitor
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 5%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5440536Monitor
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 4%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5440636Monitor
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 4%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5439935Monitor
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 1%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5440235Monitor
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 1%planet · wgr-500 firmwareOct 7, 2025
- CVE-2025-5440135Monitor
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912.
HighCVSS 8.8No exploitEPSS 1%planet · wgr-500 firmwareOct 7, 2025