Impact
The vulnerability is a command injection flaw in the /index.php/attached_devices_tab/do_upload endpoint that allows a remote attacker who can obtain operator credentials to execute arbitrary shell commands with system root privileges. This type of vulnerability falls under CWE‑78 and can lead to complete compromise of the device’s operating system, enabling the attacker to alter configurations, exfiltrate data, or use the device as a pivot point for further attacks. The CVE description explicitly states that the attacker can gain root-level control after exploitation.
Affected Systems
Affected devices are firmware for various models of Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D), and Phoenix Contact (IOL MA8 EIP DI8, IOL MA8 PN DI8). The firmware versions are not listed by the CNA, so all current releases of these devices are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity flaw; an EPSS score of 2 % suggests a moderate likelihood of exploitation in the near future. The vulnerability is not listed in CISA KEV, but that does not reduce the relevance to affected operators. Inferred from the description, the attack vector is remote over the network, requiring operator authentication to the device; therefore, compromised credentials or social engineering could provide the necessary access. Once authenticated, the attacker can trigger the command injection to run arbitrary commands as root, which can lead to full device takeover.
OpenCVE Enrichment