{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/planet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:planet:gs_4210_16p2s:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-75121"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GS-4210-16P2S (\u003c 3.441b260626)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-75121","command-injection","network-security"],"_cs_type":"advisory","_cs_vendors":["PLANET"],"content_html":"\u003cp\u003ePLANET GS-4210-16P2S network switches running firmware versions prior to 3.441b260626 are susceptible to an authenticated OS command injection vulnerability. The flaw exists within the /cgi-bin/dispatcher.cgi endpoint, specifically handled by the web_vlan_membership_edit_dialog_post function. An attacker with valid administrative or authenticated credentials can craft a malicious HTTP POST request containing a manipulated memberTags parameter. Because the application fails to properly sanitize this input before passing it to the underlying system shell, an attacker can execute arbitrary operating-system commands with the privileges of the web management process. This vulnerability is tracked as CVE-2026-75121 and poses a significant risk for lateral movement or persistence on the internal network through compromised networking infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to gain full command execution on the target GS-4210-16P2S switch. This can lead to unauthorized configuration changes, traffic interception, network reconnaissance, or the use of the switch as a staging point for further attacks within the local area network. Given the role of these devices in managing VLANs and internal traffic, compromise could have broad ramifications for internal segmentation and security policy enforcement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams include:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatching: Update all PLANET GS-4210-16P2S devices to firmware version 3.441b260626 or later immediately.\u003c/li\u003e\n\u003cli\u003eAccess Control: Limit access to the device web management interface to trusted administrative IPs only using hardware-based ACLs or isolated management VLANs.\u003c/li\u003e\n\u003cli\u003eCredential Management: Audit and rotate all administrative credentials on PLANET switches to reduce the risk of unauthorized access required for this exploitation.\u003c/li\u003e\n\u003cli\u003eMonitoring: Monitor web server access logs for anomalous POST requests to /cgi-bin/dispatcher.cgi, particularly those containing shell metacharacters in the memberTags field.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:37:31Z","date_published":"2026-08-28T21:37:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-planet-command-injection/","summary":"PLANET GS-4210-16P2S switches running firmware older than 3.441b260626 are vulnerable to authenticated OS command injection via the memberTags parameter.","title":"Authenticated OS Command Injection in PLANET GS-4210-16P2S","url":"https://feed.craftedsignal.io/briefs/2026-08-planet-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - PLANET","version":"https://jsonfeed.org/version/1.1"}