CVE-2026-75122
nicheAuthenticated Command Injection in PLANET GS-4210-16P2S V3 Switch Firmware
CVE-2026-75122 is an authenticated OS command injection (CWE-78) in the /cgi-bin/httpuploadcert.cgi endpoint of PLANET GS-4210-16P2S V3 switch firmware, where the certificate password field from a certificate upload request is inserted into a shell command without sanitization of shell metacharacters. An attacker holding administrator credentials for the switch's web interface can submit a crafted certificate upload request with shell metacharacters in the password field, causing arbitrary operating-system commands to run on the device. Successful exploitation gives full command execution on the switch (CVSS 4.0 scores complete confidentiality, integrity and availability impact on the vulnerable system), enabling configuration or firmware tampering, credential theft, and use of the switch as a foothold into the attached network. Only units running V3 firmware prior to 3.441b260626 are affected, and exposure is further limited because exploitation requires valid administrator web credentials. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns about 0.8% probability of exploitation in the next 30 days (53rd percentile), so active exploitation risk is currently low.
What to do: Upgrade affected switches to V3 firmware 3.441b260626 or later. Until patched, restrict the web management interface to trusted management networks, enforce strong unique administrator credentials, and review device logs for unexpected certificate upload activity. Check devices that cannot yet be upgraded for signs of tampering, such as unexpected processes, config changes, or new credentials.
| PLANET Technology GS-4210-16P2S (V3) PoE switch | V3 firmware before 3.441b260626 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute arbitrary operating-system commands on the device.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.