Impact
A command injection flaw exists in the /index.php/ajax/get_iodd_port_info endpoint of certain Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact devices. The vulnerability allows a low‑privileged remote attacker who already holds user or operator credentials to inject arbitrary shell commands. Because the injected commands run with the operating system’s root privilege, the attacker can fully compromise the device, read or modify configuration, and potentially spread to other network assets. The flaw is a classic instance of CWE‑78 Command Injection.
Affected Systems
Affected products include Carlo Gavazzi Automation YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO; Pepperl+Fuchs ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D; and Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8. Firmware versions are not enumerated in the advisory, so all current releases of these devices are potentially vulnerable unless a specific remedial firmware has been applied.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity vulnerability, and the EPSS score of 2% indicates this issue is not among the most frequently exploited problems but remains a real threat because it permits root‑level command execution. Because it requires authenticated access, an attacker first needs to obtain valid user or operator credentials; after that, the endpoint can be targeted with a crafted request that executes arbitrary commands. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been documented at the time of this advisory. Nonetheless, the combination of remote command injection and root execution warrants urgent remediation.
OpenCVE Enrichment