ZeroHour

CVE-2026-75121

moderate

Authenticated OS command injection in PLANET GS-4210-16P2S V3 switches

CVSS 4.0
8.6 high
EPSS
1%p65
Published
()
Modified
AI analysis

PLANET GS-4210-16P2S V3 switches running firmware before 3.441b260626 contain an OS command injection flaw (CWE-78) in the web UI handler web_vlan_membership_edit_dialog_post of /cgi-bin/dispatcher.cgi. The handler takes the memberTags POST parameter, supplied when editing VLAN membership, and inserts it into a shell command without sanitization, so a crafted value executes arbitrary operating-system commands on the device. A remote attacker who has valid web UI credentials — high-privilege access per the CVSS 4.0 vector — can run commands with the switch's privileges, which typically means full control of the device. Only GS-4210-16P2S units on hardware revision V3 with affected firmware are impacted. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS puts the 30-day exploitation probability at about 1.1%.

What to do: Upgrade affected GS-4210-16P2S V3 units to firmware 3.441b260626 or later. Until patched, restrict access to the switch web UI (allowlisting or VPN), use strong unique admin credentials, and monitor VLAN-membership edit activity for anomalies. Confirm the hardware revision is V3 on the device label or web UI, as only that revision is named in the advisory.

Affected
PLANET Technology GS-4210-16P2S V3 (switch firmware)before 3.441b260626
Estimated exposure
moderate≈ thousands of deployed units, with the internet-exposed subset likely in the low thousands (single-SKU SMB/ISP switch; no published install count) — The affected product is one specific 16-port managed PoE switch model and hardware revision from a Taiwan-based vendor that serves SMB and ISP deployments, which plausibly ship in the thousands to low tens of thousands, and many such…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.