Impact
An authenticated command injection flaw exists in the dispatcher.cgi web_smtp_test_post handler of the PLANET GS-4210-16P2S firmware. The handler incorporates a caller-supplied SMTP server value directly into a shell command without any sanitization, allowing a remote attacker who possesses administrator web credentials to execute arbitrary operating‑system commands on the device. This represents a classic OS command injection (CWE-78) that can compromise confidentiality, integrity, and availability of the device and any network resources it connects to.
Affected Systems
Planet Technology Corp. sells the PLANET GS-4210-16P2S router. Versions of the firmware before 3.441b260626 are vulnerable. The flaw resides in the web interface component /cgi-bin/dispatcher.cgi on those affected devices.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is unavailable but the vulnerability is not listed in the CISA KEV catalog. Remote exploitation requires valid administrator credentials; however, if credentials are leaked or brute‑forced, the attacker can run arbitrary shell commands. Because the flaw is authenticated, the risk is lower for exposed public interfaces but remains serious for internal or remote users who may gain administrative access.
OpenCVE Enrichment