CVE-2025-9972

Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Ciertos modelos de Gateway Celular Industrial desarrollados por Planet Technology tienen una vulnerabilidad de inyección de comandos del sistema operativo, permitiendo a atacantes remotos no autenticados inyectar comandos arbitrarios del sistema operativo y ejecutarlos en el dispositivo.

23 Sep 2025, 05:15

Type Values Removed Values Added
Summary (en) The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server. (en) Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.

17 Sep 2025, 11:15

Type Values Removed Values Added
References
  • () https://www.planet.com.tw/en/support/security-advisory/8 -

17 Sep 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-17 07:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-9972

Mitre link : CVE-2025-9972

CVE.ORG link : CVE-2025-9972


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')