CVE-2026-81942
8.8PLANET Technology Corp. · IGS-5225-8P2T4S
PLANET IGS-5225-8P2T4S switches contain an OS command injection vulnerability in the web server, allowing authenticated attackers to execute arbitrary system commands and escalate privileges to root.
Executive summary
An OS command injection vulnerability in the PLANET IGS-5225-8P2T4S web interface allows authenticated attackers to gain full root-level control over the device.
Vulnerability
The device suffers from an OS command injection flaw where user-supplied input is passed to the system() function without adequate filtering. This vulnerability requires the attacker to be authenticated as a user, after which they can execute arbitrary operating system commands with root privileges.
Business impact
A successful exploit grants an attacker full root access to the industrial managed switch, which could lead to total compromise of network traffic, unauthorized configuration changes, or the use of the device as a pivot point for further lateral movement within the industrial network. Given the CVSS score of 8.8, this vulnerability represents a high risk to operational integrity and security, potentially resulting in significant service disruption or unauthorized control over physical infrastructure.
Remediation
Immediate Action: Update the firmware on all affected IGS-5225-8P2T4S devices to version 1.2412b260707 (for V1) or 2.2412b260519 (for V2) immediately.
Proactive Monitoring: Monitor system logs for unusual command execution patterns or unauthorized attempts to access administrative web functions.
Compensating Controls: Restrict access to the web management interface to trusted management IP addresses via an internal firewall or access control list to prevent unauthorized users from reaching the vulnerable endpoint.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the severity of this command injection flaw and the potential for full device compromise, administrators should prioritize applying the vendor-provided firmware updates. Ensure all networking equipment is isolated from public exposure and maintain strict control over administrative access to mitigate the risk of exploitation while the patching process is underway.
More PLANET Technology Corp. CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Maksim Gruzin, with Ivan Kurnakov, Vladimir Nazarov, Ilya Bubliy, Iliya Rogachev, Arseny Grigorev, Ivan Tarakanov, Aleksey Karimov (positive (finder), per the CVE Program record.
- Vendor Advisory Vendor advisory
- Third-party advisory