CVE-2026-81942

Summary

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.

Affected Software

VendorProductVersion RangeStatus
PLANET Technology Corp.PLANET IGS-5225-8P2T4S V10 < 1.2412b260707affected
PLANET Technology Corp.PLANET IGS-5225-8P2T4S V20 < 2.2412b260519affected

Weaknesses

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References