Junglewise Threat Intelligence

CVE-2026-75122: PLANET GS-4210-16P2S V3 OS command injection in certificate upload

CVE-2026-75122 · Severity: high · CVSS 7.2 · Published 2026-08-28

Technologies: PLANET GS-4210-16P2S V3. Vendors: PLANET.

Executive brief

PLANET GS-4210-16P2S V3 is a managed network switch used to connect and control enterprise network infrastructure. This vulnerability allows an administrator with access to the web management interface to execute arbitrary system commands on the switch by uploading a malicious certificate, potentially compromising the device's security and allowing lateral movement into the network.

Technical details

This is an authenticated OS command injection vulnerability (CWE-78) in the /cgi-bin/httpuploadcert.cgi endpoint. The certificate password field provided during certificate upload requests is incorporated directly into shell commands without sanitization of shell metacharacters, allowing command injection. An attacker with administrator-level web credentials can craft a malicious certificate upload request with shell metacharacters in the password field to execute arbitrary OS commands on the device. The vulnerability requires prior authentication as an administrator and network access to the web management interface. Patched firmware version 3.441b260626 and later address this issue.

Affected products

  • PLANET GS-4210-16P2S V3 before 3.441b260626

Timeline

  • 2026-08-28: disclosed

References

Related threats