CVE-2026-81942: PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch firmwareto a version that resolves this vulnerability.Fixed in 1.2412b260707 - Upgrade
Upgrade
PLANET IGS-5225-8P2T4S industrial managed switch firmwareto a version that resolves this vulnerability.Fixed in 2.2412b260519
Event History
Frequently Asked Questions
Which firmware versions need remediation?
V1 firmware before 1.2412b260707 and V2 firmware before 2.2412b260519 are affected. The provided information does not identify affected versions at or newer than those versions.
What access does an attacker need to exploit this?
The attacker must be able to reach the switch web server over the network and authenticate with a user account. No user interaction is required, and exploitation can lead to arbitrary operating-system command execution and privilege escalation to root.