OS Command Injection Vulnerability in PLANET IGS-5225-8P2T4S Industrial Managed Switch
CVE-2026-81942

8.7HIGH

What is CVE-2026-81942?

The PLANET IGS-5225-8P2T4S industrial managed switch serves as a critical component in industrial networking environments. Unfortunately, it has been identified to have an OS command injection vulnerability. This security flaw arises from insufficient input filtering in the web server, allowing authenticated remote attackers to execute arbitrary commands on the device's operating system. This can lead to privilege escalation, giving attackers root access. Users are advised to update to the latest firmware versions (V1: 1.2412b260707 and V2: 2.2412b260519) to safeguard their systems against potential exploits.

Affected Version(s)

PLANET IGS-5225-8P2T4S V1 0 < 1.2412b260707

PLANET IGS-5225-8P2T4S V2 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (Positive Technologies)
Maksim Gruzin
.