Impact
A low‑privileged remote attacker can leverage command injection in the /index.php/ajax/get_iodd_menu_info endpoint when providing valid user or operator credentials. This flaw allows execution of arbitrary shell commands with root privileges on the device, effectively giving the attacker full control over the system. The vulnerability is a classic example of CWE‑78 – OS command injection, and it directly compromises confidentiality, integrity, and availability of the affected control devices.
Affected Systems
The flaw affects firmware on a range of industrial control products from Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact. Specific models include YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, IOL MA8 EIP DI8, and IOL MA8 PN DI8. No specific firmware version was disclosed, so any device running firmware that still contains the vulnerable /index.php/ajax/get_iodd_menu_info code block is potentially at risk.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is classified as High, and the EPSS score of 2% indicates that, although exploitation is not yet widespread, attackers may target these devices when the opportunity arises. The flaw is not listed in CISA’s KEV catalog, but attackers would need valid credentials to reach the endpoint. Likely the attack vector is remote over the web interface, wherein an authenticated user could send crafted input to the AJAX endpoint and trigger system‑level commands with root privileges.
OpenCVE Enrichment