Executive brief
The PLANET GS-4210-16P2S V3 is a managed gigabit network switch used in corporate environments. An authenticated administrator can inject arbitrary operating system commands through the web management interface, gaining full control over the device. This allows an attacker with management credentials to compromise network infrastructure, manipulate network traffic, or cause service outages.
Technical details
OS command injection (CWE-78) in the web_vlan_membership_edit_dialog_post handler of /cgi-bin/dispatcher.cgi. The memberTags POST parameter is directly concatenated into a shell command without sanitization of metacharacters, allowing injection of arbitrary commands. The vulnerability requires authentication with administrator-level web-management privileges; an attacker must provide valid credentials to reach the vulnerable endpoint. Successful exploitation grants command execution with the privileges of the CGI process, enabling full device compromise. Firmware version 3.441b260626 and later contain the fix.
Affected products
- PLANET GS-4210-16P2S V3 before 3.441b260626
Timeline
- 2026-08-28: disclosed