<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>GS-4210-16P2S (&lt; 3.441b260626) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gs-4210-16p2s--3.441b260626/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:37:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gs-4210-16p2s--3.441b260626/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authenticated OS Command Injection in PLANET GS-4210-16P2S</title><link>https://feed.craftedsignal.io/briefs/2026-08-planet-command-injection/</link><pubDate>Fri, 28 Aug 2026 21:37:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-planet-command-injection/</guid><description>PLANET GS-4210-16P2S switches running firmware older than 3.441b260626 are vulnerable to authenticated OS command injection via the memberTags parameter.</description><content:encoded><![CDATA[<p>PLANET GS-4210-16P2S network switches running firmware versions prior to 3.441b260626 are susceptible to an authenticated OS command injection vulnerability. The flaw exists within the /cgi-bin/dispatcher.cgi endpoint, specifically handled by the web_vlan_membership_edit_dialog_post function. An attacker with valid administrative or authenticated credentials can craft a malicious HTTP POST request containing a manipulated memberTags parameter. Because the application fails to properly sanitize this input before passing it to the underlying system shell, an attacker can execute arbitrary operating-system commands with the privileges of the web management process. This vulnerability is tracked as CVE-2026-75121 and poses a significant risk for lateral movement or persistence on the internal network through compromised networking infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to gain full command execution on the target GS-4210-16P2S switch. This can lead to unauthorized configuration changes, traffic interception, network reconnaissance, or the use of the switch as a staging point for further attacks within the local area network. Given the role of these devices in managing VLANs and internal traffic, compromise could have broad ramifications for internal segmentation and security policy enforcement.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams include:</p>
<ul>
<li>Patching: Update all PLANET GS-4210-16P2S devices to firmware version 3.441b260626 or later immediately.</li>
<li>Access Control: Limit access to the device web management interface to trusted administrative IPs only using hardware-based ACLs or isolated management VLANs.</li>
<li>Credential Management: Audit and rotate all administrative credentials on PLANET switches to reduce the risk of unauthorized access required for this exploitation.</li>
<li>Monitoring: Monitor web server access logs for anomalous POST requests to /cgi-bin/dispatcher.cgi, particularly those containing shell metacharacters in the memberTags field.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-75121</category><category>command-injection</category><category>network-security</category></item></channel></rss>