Skip to content
High-Risk OS Command Injection Vulnerability in PLANET IGS-5225 Switches

High-Risk OS Command Injection Vulnerability in PLANET IGS-5225 Switches

First seen 19 Sep 2026, 01:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 01:58 UTC
  • CVE-2026-81942 allows remote command execution on affected switches.
  • Firmware versions prior to 1.2412b260707 and 2.2412b260519 are vulnerable.
  • Immediate firmware updates and access restrictions are critical for mitigation.

PLANET Technology Corp. has disclosed a critical OS command injection vulnerability (CVE-2026-81942) affecting the IGS-5225-8P2T4S industrial managed switch firmware versions prior to 1.2412b260707 and 2.2412b260519. This vulnerability allows remote authenticated attackers to execute arbitrary commands on the underlying operating system, potentially escalating privileges to root. The CVSS v4.0 score for this vulnerability is 8.7, indicating a high severity level. Other related vulnerabilities include CVE-2026-81943, CVE-2026-81944, and CVE-2026-81945, which also present significant risks. Organizations using these switches in poorly segregated networks are particularly vulnerable. Immediate action is required to mitigate risks, including upgrading firmware and restricting access to management interfaces. The vulnerability was published on September 18, 2026, and is currently not known to be actively exploited.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-18
CVE-2026-81942 published
PLANET Technology Corp. disclosed an OS command injection vulnerability in their IGS-5225 switches.
Redpacketsecurity
2026-09-18
Multiple CVEs published
CVE-2026-81943, CVE-2026-81944, and CVE-2026-81945 were also disclosed, highlighting additional vulnerabilities.
www.planet.com.tw
2026-09-18
CVE-2026-81945 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-81944 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-81943 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
CVE-2026-81946 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-19
Urgent advisory issued
Security professionals are urged to upgrade firmware and restrict access to mitigate risks from the vulnerabilities.
www.redpacketsecurity.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-81942 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed