Impact
An attacker with high privileges can exploit the /api/status/data endpoint by submitting a specially crafted DELETE request that includes administrator credentials. This flaw allows arbitrary shell commands to be executed on the device as root, giving the attacker complete control over the affected hardware. The vulnerability is a classic command injection case and is classified as CWE‑78. A successful exploitation would grant the attacker full confidentiality, integrity, and availability compromise for the affected device.
Affected Systems
The flaw impacts firmware on a range of Carlo Gavazzi Automation such as the YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, and YN115CPN8RPIO are affected ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑ ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D, and related firmware variants are listed as vulnerable. Phoenix Contact devices such as the IOL MA8 EIP DI8 and IOL MA8 PN DI8 firmware also contain the flaw.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity of risk. An EPSS score of 2 % means the probability of exploitation is currently low but not negligible and a recent lack of listing in CISA KEV suggests no widespread public exploit is documented. The attack requires that the attacker already possesses valid administrator credentials and network connectivity to the device’s management interface. Once those prerequisites are met, the attacker can issue a DELETE request that injects shell commands, which are then executed with root privileges on the firmware. This would allow complete takeover of the device. Given the critical nature of the affected industrial controllers, the exploitation would have significant operational impact.
OpenCVE Enrichment