Impact
The PLANET GS-4210-16P2S V3 firmware before 3.441b260626 includes an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller‑supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web credentials can send a crafted SMTP server value to execute arbitrary operating‑system commands. This flaw enables the attacker to run commands with the device’s system privileges, potentially compromising confidentiality, integrity, and availability of the device and any connected network resources.
Affected Systems
Planet Technology Corp. sells the PLANET GS-4210-16P2S router. Versions of the firmware before 3.441b260626 are vulnerable. The flaw resides in the web interface component /cgi-bin/dispatcher.cgi on those affected devices.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score of 1% indicates a relatively low probability of exploitation, although it is not negligible; the vulnerability is not listed in the CISA KEV catalog. Remote exploitation requires valid administrator credentials; however, if credentials are leaked or brute‑forced, the attacker can run arbitrary shell commands. Because the flaw is authenticated, the risk is lower for exposed public interfaces but remains serious for internal or remote users who may gain administrative access.
OpenCVE Enrichment