CyberRota Analysis
AI-GeneratedThe firmware of PLANET GS-4210-16P2S devices prior to version 3.441b260626 is vulnerable to an authenticated OS command injection due to improper sanitization of the memberTags POST parameter in the web_vlan_membership_edit_dialog_post handler. This flaw allows a remote authenticated attacker to execute arbitrary operating system commands, potentially compromising the device's integrity and security. Organizations using this firmware should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the device.