Description
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
Published: 2026-09-16
Score: 8.8 High
EPSS: 2.1% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw exists in the /index.php/ajax/parameterManage endpoint of the affected devices. A remote attacker with only low privileges can submit specially crafted input that is executed as the operating system’s root user. Successful exploitation gives the attacker full control over the device, allowing data exfiltration, configuration changes, or further network compromise.

Affected Systems

The vulnerability impacts firmware on devices from Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ICE2 and ICE3 variants such as ICE2-8IOL-G65L-V1D, ICE3-8IOL-K45P-RJ45, among others), and Phoenix Contact (IOL MA8 EIP DI8 and PN DI8). Only the listed firmware builds are affected; no version ranges are provided.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. With an EPSS score of 2%, the likelihood of exploitation is moderate. As the flaw is not yet listed in CISA KEV, no current widespread exploit activity is reported, but the attack surface remains, especially because the endpoint is accessible to authenticated users and can be reached remotely over web protocols.

Generated by OpenCVE AI on September 16, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the firmware version of each affected device and update to a patched release provided by the vendor if one is available.
  • If a patch is not yet available, limit internet exposure by placing the device behind a firewall or VPN and blocking all external traffic to the /index.php/ajax/parameterManage endpoint.
  • Enforce strong, unique credentials and consider disabling or restricting low‑privileged accounts that can reach the vulnerable endpoint until a patch is applied.

Generated by OpenCVE AI on September 16, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
Title Command Injection in /index.php/ajax/parameterManage
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T18:36:16.745Z

Reserved: 2026-02-20T13:10:29.716Z

Link: CVE-2026-27551

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:19.188Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:37.640

Modified: 2026-09-16T19:17:11.840

Link: CVE-2026-27551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')