Impact
An OS command injection flaw exists in the web server of PLANET IGS-5225-8P2T4S managed switches. User input supplied to certain endpoints is forwarded to the system() call without adequate sanitization. The vulnerability allows a remote authenticated attacker to supply arbitrary shell commands, which are then executed with the privileges of the web server process. This can lead to full compromise of the underlying operating system, including privilege escalation to root on the device.
Affected Systems
PLANET Technology Corp. sells the IGS-5225-8P2T4S managed switch in two firmware lineages: version V1 and V2. Firmware releases before 1.2412b260707 for V1 and before 2.2412b260519 for V2 are affected. These devices are deployed in industrial control environments and are typically accessed via the web interface.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating a high severity. EPSS Score is 2%, but the lack of a listed KEV entry suggests no publicly known exploits yet. The attack requires remote authenticated access to the web interface, implying prior credential compromise or unwarranted administrative access is necessary. Once achieved, the attacker can run arbitrary commands and gain root, leading to full system compromise.
OpenCVE Enrichment