Description
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.
Published: 2026-08-28
Score: 8.6 High
EPSS: 1.1% Low
KEV: No
Impact: Remote Command Execution
Action: Patch
AI Analysis

Impact

The vulnerability is an authenticated OS command injection in the /cgi-bin/dispatcher.cgi script of the GS‑4210‑16P2S firmware. The web_vlan_membership_edit_dialog_post handler concatenates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating‑system commands on the device, compromising confidentiality, integrity, and availability.

Affected Systems

The affected product is PLANET GS‑4210‑16P2S. Firmware versions prior to 3.441b260626 are vulnerable. Devices running the latest firmware or any later release where the command concatenation has been removed are not impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed over the web interface by anyone who can authenticate to the device, so the required access privileges are relatively low within the context of the management network. Given the high impact and the lack of strong mitigation on the vendor side, the risk remains significant until a firmware update is applied or the exposure is otherwise constrained.

Generated by OpenCVE AI on September 2, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GS‑4210‑16P2S firmware to version 3.441b260626 or later to eliminate the command injection flaw.
  • Restrict administrative access to the management interface and disable unused web services so that only trusted personnel can reach the vulnerable script.
  • Implement network segmentation or firewall rules to isolate the device’s web management interface from the public or untrusted networks.

Generated by OpenCVE AI on September 2, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device. PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.
Title PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post PLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Planet Technology Corp
Planet Technology Corp planet Gs-4210-16p2s
Vendors & Products Planet Technology Corp
Planet Technology Corp planet Gs-4210-16p2s

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.
Title PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Planet Technology Corp Planet Gs-4210-16p2s
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-01T20:27:01.166Z

Reserved: 2026-08-17T18:39:57.660Z

Link: CVE-2026-75121

cve-icon Vulnrichment

Updated: 2026-08-31T18:40:43.163Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-28T20:19:52.567

Modified: 2026-09-08T20:20:22.260

Link: CVE-2026-75121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')