SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75122

HIGH · CVSS 7.2 EPSS 0.77%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The firmware of PLANET GS-4210-16P2S prior to version 3.441b260626 is vulnerable to an authenticated OS command injection due to improper sanitization of the certificate password field in the certificate upload process. This flaw allows a remote attacker with administrative web access to execute arbitrary operating system commands, potentially compromising the device's integrity and security. Organizations using this device should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-75122
Severity
HIGH
CVSS
7.2
EPSS
0.77%

Original NVD Description

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute arbitrary operating-system commands on the device.