Skip to content
Threat Feed
high advisory

Command Injection in PLANET IGS-5225 Industrial Switches

An OS command injection vulnerability in the web interface of PLANET IGS-5225-8P2T4S switches allows authenticated remote attackers to execute arbitrary commands with root privileges.

CVE search metadata

CVE search record: CVE-2026-81942. Severity: high. CVSS: 8.8. KEV: no. Product: IGS-5225-8P2T4S (V1 < 1.2412b260707, V2 < 2.2412b260519). Brief: Command Injection in PLANET IGS-5225 Industrial Switches. Brief link: https://feed.craftedsignal.io/briefs/2026-09-planet-switch-rce/

PLANET Technology IGS-5225-8P2T4S industrial managed switches (V1 and V2) are affected by an OS command injection vulnerability within the embedded web server. The flaw arises from improper sanitization of user-supplied input before passing it to the system() function. An authenticated remote attacker can exploit this weakness to execute arbitrary commands on the device's underlying Linux-based operating system. Successful exploitation results in full control over the switch, allowing the attacker to escalate privileges to the root level. This vulnerability impacts V1 firmware versions prior to 1.2412b260707 and V2 firmware versions prior to 2.2412b260519. Given the nature of industrial control systems (ICS) and networking infrastructure, compromise of these devices can lead to persistent network interception, lateral movement into OT environments, or denial-of-service conditions.

Impact

Successful exploitation allows a remote authenticated attacker to gain root-level access to industrial networking infrastructure. This can facilitate unauthorized configuration changes, exfiltration of sensitive network traffic, and potential disruption of critical operational technology (OT) processes. As these switches are commonly used in industrial deployments, the risk of pivot into segmented network zones is high.

Recommendation

Update all affected PLANET IGS-5225-8P2T4S devices to the latest available firmware versions immediately (V1: >= 1.2412b260707; V2: >= 2.2412b260519). Until patching is complete, restrict access to the web-based management interface to trusted management subnets only and disable HTTP/HTTPS access where not strictly required for operations.


Immediate actions

Upgrade IGS-5225-8P2T4S to 1.2412b260707 or later

IT Operations 48h

Mitigations

Restrict management interface network access to authorized segments

immediate OT Security

CVE-2026-81942