Description
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.
Published: 2026-08-28
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in a web management script in the GS-4210-16P2S firmware. An authenticated attacker can craft a POST request that inserts a supplied memberTags value directly into a shell command without any sanitization. This allows execution of arbitrary operating‑system commands on the device, compromising the confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is PLANET GS-4210-16P2S. Firmware versions prior to 3.441b260626 are vulnerable. Devices running the latest firmware or any later release where the command concatenation has been removed are not impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed over the web interface by anyone who can authenticate to the device, so the required access privileges are relatively low within the context of the management network. Given the high impact and the lack of strong mitigation on the vendor side, the risk remains significant until a firmware update is applied or the exposure is otherwise constrained.

Generated by OpenCVE AI on August 28, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GS-4210-16P2S firmware to version 3.441b260626 or later to eliminate the command injection flaw.
  • Restrict administrative access to the management interface and disable unused web services so that only trusted personnel can reach the vulnerable script.
  • Implement network segmentation or firewall rules to isolate the device’s web management interface from the public or untrusted networks.

Generated by OpenCVE AI on August 28, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.
Title PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T15:29:54.168Z

Reserved: 2026-08-17T18:39:57.660Z

Link: CVE-2026-75121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T20:19:52.567

Modified: 2026-08-28T20:19:52.567

Link: CVE-2026-75121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')