ZeroHour

CVE-2026-75123

niche

Authenticated OS Command Injection in PLANET GS-4210-16P2S V3 Switch

CVSS 4.0
8.6 high
EPSS
1%p65
Published
()
Modified
AI analysis

CVE-2026-75123 is an authenticated OS command injection flaw (CWE-78) in the web management interface of the PLANET GS-4210-16P2S V3 switch, located in the web_smtp_test_post handler of /cgi-bin/dispatcher.cgi. A remote attacker who already holds valid administrator web credentials triggers it by submitting a crafted SMTP server value, which the handler embeds directly into a shell command without sanitization. Successful exploitation allows arbitrary operating-system commands to run on the switch, with high-rated impact on the device's confidentiality, integrity, and availability per the CVSS 4.0 score of 8.6. Only GS-4210-16P2S V3 units running firmware prior to 3.441b260626 are affected, and exploitation requires administrator-level web access, so exposure is limited to deployments where attackers can reach the management interface. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and the CVE is not in CISA KEV; EPSS assigns a 1.1% probability of exploitation within 30 days (65th percentile).

What to do: Upgrade affected GS-4210-16P2S V3 units to firmware 3.441b260626 or later from PLANET. Until patched, restrict access to the web management interface to trusted networks, ensure administrator credentials are strong and not vendor defaults, and avoid using the SMTP test function with untrusted input. Review device logs for unexpected SMTP server values or shell command activity that could indicate prior exploitation.

Affected
PLANET GS-4210-16P2S V3 switchV3 firmware before 3.441b260626 (fixed in 3.441b260626)
Estimated exposure
nichelikely on the order of thousands of deployed units worldwide, with internet-exposed management interfaces plausibly in the hundreds to low thousands — This estimate is based on deployment patterns: PLANET is a mid-tier networking vendor, this is a single hardware revision of one switch model commonly used in SMB, ISP, and IP-surveillance networks where management pages are typically kept…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web credentials can send a crafted SMTP server value to execute arbitrary operating-system commands on the device.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.