attack that could allow an unauthenticated attacker to execute OS
commands on the host system.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Planet Technology has released patches for the following devices: * WGS-804HPT (v2) https://www.planet.com.tw/en/product/wgs-804hpt-v2 * WGS-4215-8T2 https://www.planet.com.tw/en/product/wgs-4215-8t2s * S https://www.planet.com.tw/en/product/wgs-4215-8t2s UNI-NMS https://www.planet.com.tw/en/product/uni-nms * NMS-500 https://www.planet.com.tw/en/product/nms-500 * NMS-1000V https://www.planet.com.tw/en/product/nms-1000v
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11973 | WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system. |
Fri, 25 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Apr 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system. | |
| Title | Planet Technology Network Products OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-25T15:59:56.581Z
Reserved: 2025-04-22T15:31:46.237Z
Link: CVE-2025-46272
Updated: 2025-04-25T15:59:30.434Z
Status : Deferred
Published: 2025-04-24T23:15:15.513
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-46272
No data.
OpenCVE Enrichment
No data.
EUVD