Authenticated OS Command Injection Vulnerability in PLANET GS-4210-16P2S Firmware
Article Content
CVE-2026-75121 is an authenticated OS command injection vulnerability found in the PLANET GS-4210-16P2S firmware, specifically in the /cgi-bin/dispatcher.cgi endpoint. The vulnerability arises from the failure to properly sanitize the memberTags POST parameter, allowing authenticated attackers with high privileges to execute arbitrary commands on the device. Currently, there is no evidence of public proof-of-concept or confirmed exploitation in the wild. A patch has been released, and users are advised to update to firmware version 3.441b260626 or later. Additionally, restricting network access to the device's web management interface is recommended to mitigate risks. The CVSS base score assigned to this vulnerability is 7.2, indicating a high severity level. The vulnerability was published on August 28, 2026, and has been reported by multiple sources.
Key Points: • CVE-2026-75121 affects PLANET GS-4210-16P2S firmware before version 3.441b260626. • The vulnerability allows authenticated attackers to execute arbitrary OS commands. • A patch is available, and users are urged to update their firmware immediately.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.