Impact
A low‑privileged remote attacker can trigger a command‑injection flaw by sending a specially crafted GET request to the /api/status/data endpoint. The vulnerability allows the attacker to execute arbitrary shell commands with root privileges on the device’s firmware, granting full control over configuration and the ability to disrupt operations, compromise confidentiality, integrity, and availability.
Affected Systems
The affected devices include firmware from Carlo Gavazzi Automation – models YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO; Pepperl+Fuchs – ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D; and Phoenix Contact – IOL MA8 EIP DI8 and IOL MA8 PN DI8. No specific firmware version numbers are listed in the CVE details.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while the EPSS of 2% indicates a moderate probability of exploitation. The flaw is not yet listed in the CISA KEV catalog. Attackers require only low‑privilege remote access to the device’s web API and can embed shell metacharacters into the GET request to achieve root‑level command execution, affecting the device’s confidentiality, integrity, and availability.
OpenCVE Enrichment