Description
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
Published: 2026-09-16
Score: 8.8 High
EPSS: 2.1% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a command injection flaw in the /index.php/attached_devices_tab/do_upload endpoint that allows a remote attacker who can obtain operator credentials to execute arbitrary shell commands with system root privileges. This type of vulnerability falls under CWE‑78 and can lead to complete compromise of the device’s operating system, enabling the attacker to alter configurations, exfiltrate data, or use the device as a pivot point for further attacks. The CVE description explicitly states that the attacker can gain root-level control after exploitation.

Affected Systems

Affected devices are firmware for various models of Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D), and Phoenix Contact (IOL MA8 EIP DI8, IOL MA8 PN DI8). The firmware versions are not listed by the CNA, so all current releases of these devices are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity flaw; an EPSS score of 2 % suggests a moderate likelihood of exploitation in the near future. The vulnerability is not listed in CISA KEV, but that does not reduce the relevance to affected operators. Inferred from the description, the attack vector is remote over the network, requiring operator authentication to the device; therefore, compromised credentials or social engineering could provide the necessary access. Once authenticated, the attacker can trigger the command injection to run arbitrary commands as root, which can lead to full device takeover.

Generated by OpenCVE AI on September 16, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by the device manufacturer for all affected models to fix the command injection flaw.
  • Restrict or disable the use of operator credentials on the /index.php endpoint and enforce least‑privilege access controls for device configuration.
  • Segment the device network and block remote access from uncontrolled sources; use VLAN or firewall rules to limit exposure of the management interface.
  • Monitor authentication logs for repeated failed login attempts or unusual command usage indicating an exploitation attempt.

Generated by OpenCVE AI on September 16, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
Title Command Injection in /index.php/attached_devices_tab/do_upload
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T18:25:16.526Z

Reserved: 2026-02-20T13:10:29.715Z

Link: CVE-2026-27549

cve-icon Vulnrichment

Updated: 2026-09-16T18:25:08.598Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:37.333

Modified: 2026-09-16T19:17:11.013

Link: CVE-2026-27549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')