Junglewise Threat Intelligence

CVE-2026-75121: PLANET GS-4210-16P2S V3 OS command injection in dispatcher.cgi

CVE-2026-75121 · Severity: high · CVSS 7.2 · Published 2026-08-28

Technologies: PLANET GS-4210-16P2S V3. Vendors: PLANET.

Executive brief

The PLANET GS-4210-16P2S V3 is a managed gigabit network switch used in corporate environments. An authenticated administrator can inject arbitrary operating system commands through the web management interface, gaining full control over the device. This allows an attacker with management credentials to compromise network infrastructure, manipulate network traffic, or cause service outages.

Technical details

OS command injection (CWE-78) in the web_vlan_membership_edit_dialog_post handler of /cgi-bin/dispatcher.cgi. The memberTags POST parameter is directly concatenated into a shell command without sanitization of metacharacters, allowing injection of arbitrary commands. The vulnerability requires authentication with administrator-level web-management privileges; an attacker must provide valid credentials to reach the vulnerable endpoint. Successful exploitation grants command execution with the privileges of the CGI process, enabling full device compromise. Firmware version 3.441b260626 and later contain the fix.

Affected products

  • PLANET GS-4210-16P2S V3 before 3.441b260626

Timeline

  • 2026-08-28: disclosed

References

Related threats