Impact
The command injection vulnerability resides at /index.php/ajax/get_iodd_port_info. It allows a low‑privileged authenticated remote attacker to inject arbitrary shell commands which will execute with root privileges on the device. This grants the attacker full control over the device's operating system.
Affected Systems
Affected products include Carlo Gavazzi Automation YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO; Pepperl+Fuchs ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D; and Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8. Firmware versions are not specified in the advisory, so all current releases of these devices are potentially vulnerable unless a firmware fix has been applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability, and the EPSS score of 2% suggests a moderate probability of exploitation. The flaw requires authenticated access (user or operator credentials) but can be triggered remotely via the web interface. It is not listed in the CISA KEV catalog and no public exploits have been reported to date. Because the attack allows root‑level command execution, it poses a significant risk to device integrity and confidentiality, making remediation a priority.
OpenCVE Enrichment