Impact
A low‑privileged remote attacker can craft an HTTP request to the /index.php/attached_devices_tab supplying operator credentials. The request is processed without proper input validation, allowing arbitrary shell commands to be executed with root privileges on the device. This command injection flaw (CWE‑78) enables the attacker to gain complete control of the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability impacts firmware on devices from Carlo Gavazzi Automation (models YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs ICE2 and ICE3 series (models ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D) and Phoenix Contact IOL MA8 EIP DI8 and PN DI8 models. No specific affected-version information is available.
Risk and Exploitability
The flaw scores 8.8 on the CVSS scale, indicating high severity, and has an EPSS score of 2%, suggesting that exploitation is relatively uncommon but not negligible. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most likely attack vector is a remote network‑based web attack where an attacker authenticates with operator credentials and submits a malicious request to the vulnerable endpoint, resulting in root‑level command execution.
OpenCVE Enrichment