CVE-2026-75123
nicheAuthenticated OS Command Injection in PLANET GS-4210-16P2S V3 Switch
CVE-2026-75123 is an authenticated OS command injection flaw (CWE-78) in the web management interface of the PLANET GS-4210-16P2S V3 switch, located in the web_smtp_test_post handler of /cgi-bin/dispatcher.cgi. A remote attacker who already holds valid administrator web credentials triggers it by submitting a crafted SMTP server value, which the handler embeds directly into a shell command without sanitization. Successful exploitation allows arbitrary operating-system commands to run on the switch, with high-rated impact on the device's confidentiality, integrity, and availability per the CVSS 4.0 score of 8.6. Only GS-4210-16P2S V3 units running firmware prior to 3.441b260626 are affected, and exploitation requires administrator-level web access, so exposure is limited to deployments where attackers can reach the management interface. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and the CVE is not in CISA KEV; EPSS assigns a 1.1% probability of exploitation within 30 days (65th percentile).
What to do: Upgrade affected GS-4210-16P2S V3 units to firmware 3.441b260626 or later from PLANET. Until patched, restrict access to the web management interface to trusted networks, ensure administrator credentials are strong and not vendor defaults, and avoid using the SMTP test function with untrusted input. Review device logs for unexpected SMTP server values or shell command activity that could indicate prior exploitation.
| PLANET GS-4210-16P2S V3 switch | V3 firmware before 3.441b260626 (fixed in 3.441b260626) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web credentials can send a crafted SMTP server value to execute arbitrary operating-system commands on the device.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.