ZeroHour

CVE-2026-75122

niche

Authenticated Command Injection in PLANET GS-4210-16P2S V3 Switch Firmware

CVSS 4.0
8.6 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-75122 is an authenticated OS command injection (CWE-78) in the /cgi-bin/httpuploadcert.cgi endpoint of PLANET GS-4210-16P2S V3 switch firmware, where the certificate password field from a certificate upload request is inserted into a shell command without sanitization of shell metacharacters. An attacker holding administrator credentials for the switch's web interface can submit a crafted certificate upload request with shell metacharacters in the password field, causing arbitrary operating-system commands to run on the device. Successful exploitation gives full command execution on the switch (CVSS 4.0 scores complete confidentiality, integrity and availability impact on the vulnerable system), enabling configuration or firmware tampering, credential theft, and use of the switch as a foothold into the attached network. Only units running V3 firmware prior to 3.441b260626 are affected, and exposure is further limited because exploitation requires valid administrator web credentials. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns about 0.8% probability of exploitation in the next 30 days (53rd percentile), so active exploitation risk is currently low.

What to do: Upgrade affected switches to V3 firmware 3.441b260626 or later. Until patched, restrict the web management interface to trusted management networks, enforce strong unique administrator credentials, and review device logs for unexpected certificate upload activity. Check devices that cannot yet be upgraded for signs of tampering, such as unexpected processes, config changes, or new credentials.

Affected
PLANET Technology GS-4210-16P2S (V3) PoE switchV3 firmware before 3.441b260626
Estimated exposure
nichelikely only hundreds to a few thousand internet-reachable units (estimate, no public install counts) — No public install-base counts or internet-exposure scan data are available for this single PLANET switch model, but as a niche managed PoE switch whose web management interface is typically kept on internal LANs, and given that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute arbitrary operating-system commands on the device.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.