CVE-2026-75123: Planet Technology Corp Planet Gs-4210-16p2s v3
High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.
PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web credentials can send a crafted SMTP server value to execute arbitrary operating-system commands on the device.
Affected products
- Planet Technology Corp Planet Gs-4210-16p2s v3: before 3.441b260626 (fixed in 3.441b260626)
Published 2026-08-28. Last modified 2026-09-08.