Impact
The vulnerability resides in the httpuploadcert.cgi script of the PLANET GS‑4210‑16P2S firmware before 3.441b260626. The script incorporates the certificate password field from a certificate upload request directly into a shell command without sanitizing shell metacharacters. An attacker who has administrator web credentials can send a crafted upload request that causes the device to execute arbitrary operating‑system commands. The weakness is a classic OS command injection (CWE‑78).
Affected Systems
PLANET Technology Corp.’s GS‑4210‑16P2S network device. Firmware versions prior to 3.441b260626 are affected; the issue originates in the web interface component of that firmware.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is 0.00765, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. Nonetheless, the attack requires administrative web credentials, but once obtained the attacker can submit a crafted upload request from any remote location to execute arbitrary OS commands. The lack of input sanitization provides a straightforward exploitation path for authenticated privileged users.
OpenCVE Enrichment