Description
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
Published: 2026-09-16
Score: 8.8 High
EPSS: 2.1% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw exists in the /index.php/ajax/get_iodd_port_info endpoint of certain Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact devices. The vulnerability allows a low‑privileged remote attacker who already holds user or operator credentials to inject arbitrary shell commands. Because the injected commands run with the operating system’s root privilege, the attacker can fully compromise the device, read or modify configuration, and potentially spread to other network assets. The flaw is a classic instance of CWE‑78 Command Injection.

Affected Systems

Affected products include Carlo Gavazzi Automation YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO; Pepperl+Fuchs ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D; and Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8. Firmware versions are not enumerated in the advisory, so all current releases of these devices are potentially vulnerable unless a specific remedial firmware has been applied.

Risk and Exploitability

The CVSS score of 8.8 signals a high‑severity vulnerability, and the EPSS score of 2% indicates this issue is not among the most frequently exploited problems but remains a real threat because it permits root‑level command execution. Because it requires authenticated access, an attacker first needs to obtain valid user or operator credentials; after that, the endpoint can be targeted with a crafted request that executes arbitrary commands. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been documented at the time of this advisory. Nonetheless, the combination of remote command injection and root execution warrants urgent remediation.

Generated by OpenCVE AI on September 16, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued firmware update that removes the command‑injection vulnerability from the /index.php/ajax/get_iodd_port_info endpoint.
  • Restrict access to the device’s web interface by firewall rules or VPN so that only trusted administrative networks can reach the endpoint.
  • Where a firmware upgrade is unavailable, disable or remove the vulnerable endpoint or apply strict input validation to prevent shell metacharacter injection.
  • Enforce strong, unique passwords for all user and operator accounts and consider disabling unused accounts to reduce the attack surface.

Generated by OpenCVE AI on September 16, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
Title Command Injection in /index.php/ajax/get_iodd_port_info
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T07:48:48.807Z

Reserved: 2026-02-20T13:10:29.715Z

Link: CVE-2026-27548

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:37.180

Modified: 2026-09-16T19:13:03.413

Link: CVE-2026-27548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')