ICS/OT

Critical Vulnerabilities Found in Planet Technology Industrial Networking Products

Planet Technology industrial switches and network management products are affected by several critical vulnerabilities. 

Planet Technology industrial switches and network management products are affected by several critical vulnerabilities. 

Industrial switches and network management products made by Taiwan-based Planet Technology are affected by several critical vulnerabilities.

The existence of the flaws came to light last week when CISA published an advisory describing five vulnerabilities discovered in Planet Technology’s UNI-NMS-Lite, NMS-500 and NMS-1000V network management systems, and WGS-804HPT-V2 and WGS-4215-8T2S switches.

The security holes have all been assigned a ‘critical’ severity rating. They can be exploited by remote, unauthenticated attackers to gain admin privileges to the affected product (through hardcoded credentials), create an admin account due to missing authentication, and conduct command injection to execute OS commands or read/manipulate device data.

CISA pointed out that the impacted devices are used worldwide, including in the critical manufacturing sector. 

Kevin Breen, senior director of cyber threat research at Immersive, who has been credited for reporting the vulnerabilities, disclosed technical details the day after CISA published its advisory. 

The researcher has shared information on how the vulnerabilities were found and how they could be exploited by threat actors. 

Advertisement. Scroll to continue reading.

According to Breen, Censys searches show hundreds and possibly thousands of potentially vulnerable Planet Technology devices that are exposed to the internet. 

The researcher discovered the vulnerabilities during the analysis of a couple of Planet Technology device flaws reported last year by industrial cybersecurity firm Claroty. 

Planet Technology has patched the vulnerabilities found by Breen — the vendor was notified on March 6 through CISA and fixes were rolled out on April 16. 

CISA said it’s not aware of the in-the-wild exploitation of these vulnerabilities.

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: Lantronix Device Used in Critical Infrastructure Exposes Systems to Remote Hacking

Related: Study Identifies 20 Most Vulnerable Connected Devices of 2025

Related: More Solar System Vulnerabilities Expose Power Grids to Hacking

Related Content

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Artificial Intelligence

Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models.

Government

The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.

ICS/OT

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

ICS/OT

Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

ICS/OT

CISA has also published several advisories describing vulnerabilities in ICS and other OT products.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version