OS Command Injection in PLANET GS-4210-16P2S Firmware
CVE-2026-75122

8.6HIGH

What is CVE-2026-75122?

The firmware of the PLANET GS-4210-16P2S device is susceptible to an OS command injection vulnerability. This flaw resides in the /cgi-bin/httpuploadcert.cgi component, where user-supplied data from the certificate password field is directly incorporated into a shell command without adequate sanitization. An attacker with administrative web credentials can exploit this weakness by sending a crafted certificate upload request, allowing them to execute arbitrary operating system commands on the affected device. This could lead to unauthorized access and control over the device, emphasizing the critical need for immediate updates to the affected firmware.

Affected Version(s)

PLANET GS-4210-16P2S V3 0 < 3.441b260626

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt)
Professor Le Yu of Nanjing University of Posts and Telecommunications
Professor Xiapu Luo of The Hong Kong Polytechnic University
.