Impact
The vulnerability exists in the httpuploadcert.cgi script of the PLANET GS-4210-16P2S firmware, where the certificate password field is concatenated into a shell command without sanitization. This allows an attacker with administrator web credentials to inject arbitrary shell commands, leading to remote code execution. The weakness is a classic OS command injection (CWE-78).
Affected Systems
PLANET Technology Corp.’s GS‑4210‑16P2S network device. Firmware versions prior to 3.441b260626 are affected; the issue originates in the web interface component of that firmware.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. Nonetheless, the attack requires administrative web credentials, but once obtained the attacker can submit a crafted upload request from any remote location to execute arbitrary OS commands. The lack of input sanitization provides a straightforward exploitation path for authenticated privileged users.
OpenCVE Enrichment