Impact
A command injection flaw exists in the /index.php/ajax/parameterManage endpoint of the affected devices. A remote attacker with only low privileges can submit specially crafted input that is executed as the operating system’s root user. Successful exploitation gives the attacker full control over the device, allowing data exfiltration, configuration changes, or further network compromise.
Affected Systems
The vulnerability impacts firmware on devices from Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ICE2 and ICE3 variants such as ICE2-8IOL-G65L-V1D, ICE3-8IOL-K45P-RJ45, among others), and Phoenix Contact (IOL MA8 EIP DI8 and PN DI8). Only the listed firmware builds are affected; no version ranges are provided.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. With an EPSS score of 2%, the likelihood of exploitation is moderate. As the flaw is not yet listed in CISA KEV, no current widespread exploit activity is reported, but the attack surface remains, especially because the endpoint is accessible to authenticated users and can be reached remotely over web protocols.
OpenCVE Enrichment