SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75121

HIGH · CVSS 7.2 EPSS 1.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The firmware of PLANET GS-4210-16P2S devices prior to version 3.441b260626 is vulnerable to an authenticated OS command injection due to improper sanitization of the memberTags POST parameter in the web_vlan_membership_edit_dialog_post handler. This flaw allows a remote authenticated attacker to execute arbitrary operating system commands, potentially compromising the device's integrity and security. Organizations using this firmware should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-75121
Severity
HIGH
CVSS
7.2
EPSS
1.15%

Original NVD Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.