Authenticated OS Command Injection Vulnerability in PLANET GS-4210-16P2S Firmware

Authenticated OS Command Injection Vulnerability in PLANET GS-4210-16P2S Firmware

First seen 30 Aug 2026, 09:47 UTC Feedlycve.reportvuldb.comnvd.nist.gov 57.0

Article Content

Browse articles
ThreatCluster

CVE-2026-75121 is an authenticated OS command injection vulnerability found in the PLANET GS-4210-16P2S firmware, specifically in the /cgi-bin/dispatcher.cgi endpoint. The vulnerability arises from the failure to properly sanitize the memberTags POST parameter, allowing authenticated attackers with high privileges to execute arbitrary commands on the device. Currently, there is no evidence of public proof-of-concept or confirmed exploitation in the wild. A patch has been released, and users are advised to update to firmware version 3.441b260626 or later. Additionally, restricting network access to the device's web management interface is recommended to mitigate risks. The CVSS base score assigned to this vulnerability is 7.2, indicating a high severity level. The vulnerability was published on August 28, 2026, and has been reported by multiple sources.

Key Points: • CVE-2026-75121 affects PLANET GS-4210-16P2S firmware before version 3.441b260626. • The vulnerability allows authenticated attackers to execute arbitrary OS commands. • A patch is available, and users are urged to update their firmware immediately.

Timeline

2026-08-28
CVE-2026-75121 published
PLANET Technology disclosed an OS command injection vulnerability in their GS-4210-16P2S firmware.
Feedly
2026-08-29
First reports of vulnerability details
Feedly published the first details regarding CVE-2026-75121, including its severity and impact.
Feedly
2026-08-30
CVE vulnerability disclosures reported
cve.report provided additional details on the vulnerability and its potential impact on users.
cve.report