Executive brief
PLANET IGS-5225-8P2T4S is an industrial managed network switch used to provide secure connectivity in critical infrastructure environments. A remote authenticated attacker can inject operating system commands through the web server interface, gaining the ability to execute arbitrary code and escalate privileges to root, potentially compromising the entire device and the networks it protects.
Technical details
The vulnerability is an OS command injection (CWE-78) in the web server where user-supplied input is passed directly to system() calls without adequate filtering. Attack requires network access and prior authentication to the device. Successful exploitation allows arbitrary command execution with root privileges, with patches available in firmware v1.2412b260707 (V1) and v2.2412b260519 (V2).
Affected products
- PLANET IGS-5225-8P2T4S V1 before 1.2412b260707
- PLANET IGS-5225-8P2T4S V2 before 2.2412b260519
Timeline
- 2026-09-18: disclosed