Impact
The vulnerability resides in a web management script in the GS-4210-16P2S firmware. An authenticated attacker can craft a POST request that inserts a supplied memberTags value directly into a shell command without any sanitization. This allows execution of arbitrary operating‑system commands on the device, compromising the confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is PLANET GS-4210-16P2S. Firmware versions prior to 3.441b260626 are vulnerable. Devices running the latest firmware or any later release where the command concatenation has been removed are not impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed over the web interface by anyone who can authenticate to the device, so the required access privileges are relatively low within the context of the management network. Given the high impact and the lack of strong mitigation on the vendor side, the risk remains significant until a firmware update is applied or the exposure is otherwise constrained.
OpenCVE Enrichment