CVE-2026-75122: PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi

Published Aug 28, 2026
·
Updated

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute arbitrary operating-system commands on the device.

Affected Software

1 affected component
Planet GS-4210-16P2S firmware<3.441b260626

Event History

Aug 28, 2026
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A remote attacker needs administrator-level web credentials for the affected device. No user interaction is required.

2

Are devices on the default configuration exposed?

The available information does not state whether default administrator credentials are present or whether the vulnerable certificate upload function is enabled by default. Exposure depends on whether an attacker can authenticate to the device's web interface with administrator privileges.

3

Which systems need updating?

PLANET GS-4210-16P2S devices running firmware earlier than 3.441b260626 are affected. Firmware 3.441b260626 is the stated fixed version threshold.

4

What can be done while patching is delayed?

Limit access to the device's web management interface to trusted administrators and networks, and protect administrator credentials. The exploit requires authenticated administrator access to submit a crafted certificate upload request.

5

How can administrators identify attempted exploitation?

Review web-management activity involving requests to /cgi-bin/httpuploadcert.cgi, particularly certificate upload requests with unusual certificate password values. Successful exploitation can execute arbitrary operating-system commands, so investigate unexpected device behavior or command-related artifacts alongside those requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203