Redpacketsecurity High-Risk OS Command Injection Vulnerability in PLANET IGS-5225 Switches
Article Content
- •CVE-2026-81942 allows remote command execution on affected switches.
- •Firmware versions prior to 1.2412b260707 and 2.2412b260519 are vulnerable.
- •Immediate firmware updates and access restrictions are critical for mitigation.
PLANET Technology Corp. has disclosed a critical OS command injection vulnerability (CVE-2026-81942) affecting the IGS-5225-8P2T4S industrial managed switch firmware versions prior to 1.2412b260707 and 2.2412b260519. This vulnerability allows remote authenticated attackers to execute arbitrary commands on the underlying operating system, potentially escalating privileges to root. The CVSS v4.0 score for this vulnerability is 8.7, indicating a high severity level. Other related vulnerabilities include CVE-2026-81943, CVE-2026-81944, and CVE-2026-81945, which also present significant risks. Organizations using these switches in poorly segregated networks are particularly vulnerable. Immediate action is required to mitigate risks, including upgrading firmware and restricting access to management interfaces. The vulnerability was published on September 18, 2026, and is currently not known to be actively exploited.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-81942 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog products. These vulnerabilities pose significant risks due to active exploitation. Concurrently, IBM has…