<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PLANET Technology - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/planet-technology/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 18:08:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/planet-technology/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in PLANET IGS-5225 Industrial Switches</title><link>https://feed.craftedsignal.io/briefs/2026-09-planet-switch-rce/</link><pubDate>Fri, 18 Sep 2026 18:08:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-planet-switch-rce/</guid><description>An OS command injection vulnerability in the web interface of PLANET IGS-5225-8P2T4S switches allows authenticated remote attackers to execute arbitrary commands with root privileges.</description><content:encoded><![CDATA[<p>PLANET Technology IGS-5225-8P2T4S industrial managed switches (V1 and V2) are affected by an OS command injection vulnerability within the embedded web server. The flaw arises from improper sanitization of user-supplied input before passing it to the system() function. An authenticated remote attacker can exploit this weakness to execute arbitrary commands on the device's underlying Linux-based operating system. Successful exploitation results in full control over the switch, allowing the attacker to escalate privileges to the root level. This vulnerability impacts V1 firmware versions prior to 1.2412b260707 and V2 firmware versions prior to 2.2412b260519. Given the nature of industrial control systems (ICS) and networking infrastructure, compromise of these devices can lead to persistent network interception, lateral movement into OT environments, or denial-of-service conditions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a remote authenticated attacker to gain root-level access to industrial networking infrastructure. This can facilitate unauthorized configuration changes, exfiltration of sensitive network traffic, and potential disruption of critical operational technology (OT) processes. As these switches are commonly used in industrial deployments, the risk of pivot into segmented network zones is high.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all affected PLANET IGS-5225-8P2T4S devices to the latest available firmware versions immediately (V1: &gt;= 1.2412b260707; V2: &gt;= 2.2412b260519). Until patching is complete, restrict access to the web-based management interface to trusted management subnets only and disable HTTP/HTTPS access where not strictly required for operations.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>