logo

Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches

ID: 2748abba-0e6d-5b44-a142-c6442a82fa7c

STIX ID: report--2748abba-0e6d-5b44-a142-c6442a82fa7c

Feed Name: Claroty Team82

Threat Score
70/100

Date Published: 2025-01-22

Date Updated: 2026-04-17

Author: Tomer Goldschmidt

...
...

This blog describes Team82's discovery of three vulnerabilities in the Planet WGS-804HPT industrial switch—including a pre-auth stack-buffer overflow in dispatcher.cgi and an OS command injection—that allow unauthenticated remote code execution. The authors explain firmware extraction, using binwalk and QEMU user/system emulation to recreate the device environment, static analysis of the Boa-based web service, remote debugging, exploit development (including MIPS shellcode) and a working PoC; the vendor was privately notified and released a firmware update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.