Description
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.
Published: 2026-09-18
Score: 8.7 High
EPSS: 1.9% Low
KEV: No
Impact: Remote command execution with root privilege escalation via OS command injection
Action: Immediate Patch
AI Analysis

Impact

An OS command injection flaw exists in the web server of PLANET IGS-5225-8P2T4S managed switches. User input supplied to certain endpoints is forwarded to the system() call without adequate sanitization. The vulnerability allows a remote authenticated attacker to supply arbitrary shell commands, which are then executed with the privileges of the web server process. This can lead to full compromise of the underlying operating system, including privilege escalation to root on the device.

Affected Systems

PLANET Technology Corp. sells the IGS-5225-8P2T4S managed switch in two firmware lineages: version V1 and V2. Firmware releases before 1.2412b260707 for V1 and before 2.2412b260519 for V2 are affected. These devices are deployed in industrial control environments and are typically accessed via the web interface.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating a high severity. EPSS Score is 2%, but the lack of a listed KEV entry suggests no publicly known exploits yet. The attack requires remote authenticated access to the web interface, implying prior credential compromise or unwarranted administrative access is necessary. Once achieved, the attacker can run arbitrary commands and gain root, leading to full system compromise.

Generated by OpenCVE AI on September 19, 2026 at 23:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware updates, specifically 1.2412b260707 or newer for V1, and 2.2412b260519 or newer for V2, which resolve the command injection issue.
  • Restrict access to the web management interface to trusted IP addresses or a dedicated management network, reducing the exposure to remote attackers.
  • Perform network segmentation so that the control network is isolated from the broader enterprise or public networks, limiting potential lateral movement from a compromised switch.
  • Enable logging and monitoring of command execution on the device, and alert on anomalous activity.

Generated by OpenCVE AI on September 19, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Planet Technology Corp
Planet Technology Corp planet Igs-5225-8p2t4s V1
Planet Technology Corp planet Igs-5225-8p2t4s V2
Vendors & Products Planet Technology Corp
Planet Technology Corp planet Igs-5225-8p2t4s V1
Planet Technology Corp planet Igs-5225-8p2t4s V2

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.
Title PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Planet Technology Corp Planet Igs-5225-8p2t4s V1 Planet Igs-5225-8p2t4s V2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:50:57.257Z

Reserved: 2026-08-27T20:41:13.615Z

Link: CVE-2026-81942

cve-icon Vulnrichment

Updated: 2026-09-21T16:42:40.729Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:10.383

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-81942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')