{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/planet-technology/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:planet_technology:igs_5225_8p2t4s:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-81942"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IGS-5225-8P2T4S (V1 \u003c 1.2412b260707, V2 \u003c 2.2412b260519)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PLANET Technology"],"content_html":"\u003cp\u003ePLANET Technology IGS-5225-8P2T4S industrial managed switches (V1 and V2) are affected by an OS command injection vulnerability within the embedded web server. The flaw arises from improper sanitization of user-supplied input before passing it to the system() function. An authenticated remote attacker can exploit this weakness to execute arbitrary commands on the device's underlying Linux-based operating system. Successful exploitation results in full control over the switch, allowing the attacker to escalate privileges to the root level. This vulnerability impacts V1 firmware versions prior to 1.2412b260707 and V2 firmware versions prior to 2.2412b260519. Given the nature of industrial control systems (ICS) and networking infrastructure, compromise of these devices can lead to persistent network interception, lateral movement into OT environments, or denial-of-service conditions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote authenticated attacker to gain root-level access to industrial networking infrastructure. This can facilitate unauthorized configuration changes, exfiltration of sensitive network traffic, and potential disruption of critical operational technology (OT) processes. As these switches are commonly used in industrial deployments, the risk of pivot into segmented network zones is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all affected PLANET IGS-5225-8P2T4S devices to the latest available firmware versions immediately (V1: \u0026gt;= 1.2412b260707; V2: \u0026gt;= 2.2412b260519). Until patching is complete, restrict access to the web-based management interface to trusted management subnets only and disable HTTP/HTTPS access where not strictly required for operations.\u003c/p\u003e\n","date_modified":"2026-09-18T18:08:23Z","date_published":"2026-09-18T18:08:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-planet-switch-rce/","summary":"An OS command injection vulnerability in the web interface of PLANET IGS-5225-8P2T4S switches allows authenticated remote attackers to execute arbitrary commands with root privileges.","title":"Command Injection in PLANET IGS-5225 Industrial Switches","url":"https://feed.craftedsignal.io/briefs/2026-09-planet-switch-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - PLANET Technology","version":"https://jsonfeed.org/version/1.1"}