Impact
An unauthenticated operator credential can trigger a command injection in the /index.php/ajax/save_iodd_parameters endpoint. The flaw, identified as CWE‑78, allows the attacker to inject arbitrary system commands that are executed with root privileges on the device. The resulting impact is full compromise of the affected hardware, enabling data exfiltration, network changes, or complete device takeover.
Affected Systems
The flaw affects several industrial control products: Carlo Gavazzi Automation YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO, Pepperl+Fuchs ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D, Phoenix Contact IOL MA8 EIP DI8, and Phoenix Contact IOL MA8 PN DI8. Specific firmware version ranges are not provided in the current data.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score of 2% suggests a moderate likelihood of exploitation. The vulnerability is not listed in CISA KEV, implying no confirmed widespread exploitation yet. Given the operator credentials required, the attack likely requires network access to the device’s web interface or API and the ability to authenticate with an operator account.
OpenCVE Enrichment