PLANET GS-4210-16P2S 固件版本早于 3.441b260626 存在一个经过身份验证的操作系统命令注入漏洞,受影响的路径为 。 在证书上传请求中,证书密码字段会被直接拼接到 shell 命令中,且未对 shell 元字符进行过滤或转义。拥有管理员 Web 凭据的远程攻击者可以提交一个精心构造的证书上传请求,从而在设备上执行任意的操作系统命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | < 3.441b260626 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PLANET Technology Corp. | PLANET GS-4210-16P2S | 0 ~ 3.441b260626 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75124 | 7.5 HIGH | PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam |
| CVE-2026-75121 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_ |
| CVE-2026-75123 | 7.2 HIGH | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post |
| CVE-2026-75126 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers |
| CVE-2026-75125 | 4.9 MEDIUM | PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_p |
| CVE-2026-77217 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi |
| CVE-2026-77218 | 4.9 MEDIUM | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Credential Handlers |
No comments yet