{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"Hard-Coded Havoc: The Fatal Flaws in Planet’s Network Devices","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/5a3bd0ad\"></iframe>","width":"100%","height":180,"duration":699,"description":"A wave of critical vulnerabilities in Planet Technology’s industrial switches and network management systems could let attackers hijack devices, steal data, and sabotage industrial networks—with no credentials required.\nIn this urgent episode, we dissect:\n🔓 The 5 worst flaws (CVSS 9.3+)—from hard-coded database passwords to pre-auth command injection—discovered by Immersive Labs’ Kev Breen.\n🏭 Why factories and critical infrastructure are prime targets: These switches are widely used in manufacturing, energy, and OT environments.\n💻 How hackers exploit them:\nMongoDB exposed? Default creds (planet:123456) let attackers dump configs.\nBypass auth entirely with a malformed URL parameter (/dispatcher.cgi?cmd=532&ip_URL=;).\nIntercept device communications due to hard-coded keys.\n🛡️ CISA’s emergency advisory (ICSA-25-114-06)—and why patching WGS, NMS, and UNI-NMS devices is non-negotiable.\n🔍 The researcher’s journey: How a home lab, firmware analysis, and a lucky accident uncovered these flaws.\nIf your network relies on Planet Technology switches, this episode is a wake-up call. Tune in before attackers beat you to the patch.","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}