CVE-2026-81942 PUBLISHED

PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server

Assigner: VulnCheck
Reserved: 27.08.2026 Published: 18.09.2026 Updated: 18.09.2026

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor PLANET Technology Corp.
Product PLANET IGS-5225-8P2T4S V1
Versions Default: unaffected
  • affected from 0 to 1.2412b260707 (excl.)
Vendor PLANET Technology Corp.
Product PLANET IGS-5225-8P2T4S V2
Versions Default: affected
  • affected from 0 to 2.2412b260519 (excl.)

Credits

  • Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (Positive Technologies) finder
  • Maksim Gruzin finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE