Impact
A command injection vulnerability exists in the /api/status/data endpoint of affected industrial controllers. An attacker who can authenticate with administrative privileges can send a crafted DELETE request that injects shell commands into the device's firmware. Because the request is executed with root privileges, the attacker can run arbitrary commands, effectively gaining full control of the device. The flaw is classified as CWE‑78, a classic command injection issue.
Affected Systems
The vulnerable firmware is found in a range of devices from three vendors. Carlo Gavazzi Automation firmware, including the YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, and YN115CPN8RPIO appliances. Pepperl+Fuchs ICE2 and ICE3 series firmware variants such as ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, and ICE3‑8IOL1‑G65L‑V1D are affected. Phoenix Contact devices including the IOL MA8 EIP DI8 and IOL MA8 PN DI8 firmware also contain the flaw.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while the EPSS score of 2 % shows the likelihood of exploitation is currently low but not negligible. The vulnerability is not listed in the CISA KEV catalog, meaning no widely known public exploit exists yet. An attacker must already possess valid administrative credentials and have network connectivity to the device's management interface; once those conditions are met, sending a malicious DELETE request results in command execution with root privileges. Successful exploitation would allow full compromise of confidentiality, integrity, and availability of the targeted industrial device.
OpenCVE Enrichment