Critical flaws in WGS-804HPT switches could be chained to gain remote code execution on Planet Technology’s industrial devices.
Claroty researchers discovered vulnerabilities in Planet WGS-804HPT industrial switches that could be chained to achieve pre-authentication remote code execution.
The vulnerabilities include buffer and integer overflow vulnerabilities and an OS command injection flaw, allowing attackers to remotely run code on the device.
Planet Technology has released firmware version 1.305b241111 to address these issues.