CVE-2026-75122: PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute arbitrary operating-system commands on the device.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker needs administrator-level web credentials for the affected device. No user interaction is required.
Are devices on the default configuration exposed?
The available information does not state whether default administrator credentials are present or whether the vulnerable certificate upload function is enabled by default. Exposure depends on whether an attacker can authenticate to the device's web interface with administrator privileges.
Which systems need updating?
PLANET GS-4210-16P2S devices running firmware earlier than 3.441b260626 are affected. Firmware 3.441b260626 is the stated fixed version threshold.
What can be done while patching is delayed?
Limit access to the device's web management interface to trusted administrators and networks, and protect administrator credentials. The exploit requires authenticated administrator access to submit a crafted certificate upload request.
How can administrators identify attempted exploitation?
Review web-management activity involving requests to /cgi-bin/httpuploadcert.cgi, particularly certificate upload requests with unusual certificate password values. Successful exploitation can execute arbitrary operating-system commands, so investigate unexpected device behavior or command-related artifacts alongside those requests.