Description
An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Confidentiality Compromise via Private Key Disclosure
Action: Patch Immediately
AI Analysis

Impact

An unauthenticated attacker can exploit a path traversal flaw in the /index.php/view_uploaded_iodd_file endpoint, enabling the download of the device’s SSH private key files. This vulnerability allows the attacker to read critical cryptographic material, potentially granting them full control over communication channels and enabling future persistence or man‑in‑the‑middle attacks. The weakness is a classic Path Traversal (CWE‑35) that bypasses normal file access restrictions.

Affected Systems

The flaw affects multiple industrial automation devices from Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact. Specific models include YL212CEI8M1IO and YL212CPN8M1IO, YN115CEI8RPIO and YN115CPN8RPIO, ICE2 and ICE3 firmware variants, and IOL MA8 EIP DI8 and IOL MA8 PN DI8 firmware. No version ranges are provided, but the vulnerability is tied to the embedded firmware that contains the vulnerable endpoint.

Risk and Exploitability

The CVSS score of 7.5 marks the issue as high severity, and the EPSS score indicates a low but non‑zero exploitation probability (<1 %). The vulnerability is not included in CISA’s KEV catalog, suggesting limited public exploitation yet. The attack can be carried out over a network by browsing to the vulnerable endpoint, after which the attacker can navigate to arbitrary files within the system’s file hierarchy. Since the exploit requires no authentication, any network access to the web interface can be used by an attacker to obtain confidential configuration data.

Generated by OpenCVE AI on September 16, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware update from the device vendor that addresses the view_uploaded_iodd_file path traversal bug
  • If a patch is not available, move the SSH private key files out of the web document root or set restrictive permissions so that web processes cannot read them
  • Restrict access to the web interface by firewall rules, VPN, or disabling the endpoint entirely if it is not required for operation

Generated by OpenCVE AI on September 16, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
Title Path Traversal in /index.php/view_uploaded_iodd_file
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-35
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T15:37:15.109Z

Reserved: 2026-02-20T13:10:29.716Z

Link: CVE-2026-27557

cve-icon Vulnrichment

Updated: 2026-09-16T15:34:26.599Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:38.520

Modified: 2026-09-16T19:13:03.413

Link: CVE-2026-27557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:15:14Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'