CreditJincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, Professor Xiapu Luo of The Hong Kong Polytechnic University DescriptionPLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.