CyberRota Analysis
AI-GeneratedThe firmware of PLANET GS-4210-16P2S prior to version 3.441b260626 is vulnerable to an authenticated OS command injection due to improper sanitization of the certificate password field in the certificate upload process. This flaw allows a remote attacker with administrative web access to execute arbitrary operating system commands, potentially compromising the device's integrity and security. Organizations using this device should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute arbitrary operating-system commands on the device.