Description
A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthorized IODD file upload enabling device configuration changes or crashes
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker to send malformed IODD files to the /index.php/attached_devices_tab/do_upload endpoint, bypassing authorization checks. By uploading a crafted file, the attacker can potentially alter firmware settings or cause the device to crash. The weakness is an improper authorization issue (CWE‑863). The impact is limited to devices that accept IODD uploads, which may lead to unintended device behavior or denial of service.

Affected Systems

Devices affected are specific models from Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ice2 and ice3 series such as ICE2‑8IOL‑G65L‑V1D, ICE3‑8IOL‑K45S‑RJ45, etc.), and Phoenix Contact (iOL MA8 EIP DI8 and iOL MA8 PN DI8). Firmware versions are indicated by the associated CPE strings, but no explicit version ranges are provided.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, yet the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in CISA KEV, so no publicly known exploit yet. The likely attack vector is remote over the network; the attacker must reach the web interface and have low‑privileged access. The absence of a publicly disclosed exploit suggests that active attack is unlikely, but the window of risk remains if device firmware is not updated.

Generated by OpenCVE AI on September 16, 2026 at 15:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade firmware to the latest version that removes the improper authorization check for the upload function.
  • If an upgrade is not immediately available, restrict network access to the /index.php/attached_devices_tab/do_upload endpoint by placing the device behind a firewall or VLAN that blocks unauthenticated access.
  • Disable or delete the IODD upload feature via device configuration or local web console to eliminate the attack surface.
  • Monitor the device logs for attempted upload requests and flag any unauthorized attempts for investigation.

Generated by OpenCVE AI on September 16, 2026 at 15:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
Title Unauthorized IODD File Upload due to Improper Authorization
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-863
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T14:53:49.707Z

Reserved: 2026-02-20T13:10:29.716Z

Link: CVE-2026-27552

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:46.235Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:37.793

Modified: 2026-09-16T19:13:03.413

Link: CVE-2026-27552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:15:14Z

Weaknesses