Impact
The vulnerability is an authenticated OS command injection in the /cgi-bin/dispatcher.cgi script of the GS‑4210‑16P2S firmware. The web_vlan_membership_edit_dialog_post handler concatenates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating‑system commands on the device, compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is PLANET GS‑4210‑16P2S. Firmware versions prior to 3.441b260626 are vulnerable. Devices running the latest firmware or any later release where the command concatenation has been removed are not impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed over the web interface by anyone who can authenticate to the device, so the required access privileges are relatively low within the context of the management network. Given the high impact and the lack of strong mitigation on the vendor side, the risk remains significant until a firmware update is applied or the exposure is otherwise constrained.
OpenCVE Enrichment