Description
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
Published: 2026-09-16
Score: 7.2 High
EPSS: 2.7% Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A command injection vulnerability exists in the /api/status/data endpoint of affected industrial controllers. An attacker who can authenticate with administrative privileges can send a crafted DELETE request that injects shell commands into the device's firmware. Because the request is executed with root privileges, the attacker can run arbitrary commands, effectively gaining full control of the device. The flaw is classified as CWE‑78, a classic command injection issue.

Affected Systems

The vulnerable firmware is found in a range of devices from three vendors. Carlo Gavazzi Automation firmware, including the YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, and YN115CPN8RPIO appliances. Pepperl+Fuchs ICE2 and ICE3 series firmware variants such as ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, and ICE3‑8IOL1‑G65L‑V1D are affected. Phoenix Contact devices including the IOL MA8 EIP DI8 and IOL MA8 PN DI8 firmware also contain the flaw.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, while the EPSS score of 2 % shows the likelihood of exploitation is currently low but not negligible. The vulnerability is not listed in the CISA KEV catalog, meaning no widely known public exploit exists yet. An attacker must already possess valid administrative credentials and have network connectivity to the device's management interface; once those conditions are met, sending a malicious DELETE request results in command execution with root privileges. Successful exploitation would allow full compromise of confidentiality, integrity, and availability of the targeted industrial device.

Generated by OpenCVE AI on September 18, 2026 at 10:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version that removes the vulnerable endpoint or sanitizes the DELETE request input. This is the official fix issued by the vendors.
  • Constrain network access to the device’s management interface so that only trusted internal networks or VPN connections can reach it; block all external traffic with firewalls or ACLs.
  • Enforce strict authentication policies, limiting administrative login to a minimal set of users, applying role‑based access control, and encouraging multi‑factor authentication to reduce the risk of credential compromise.

Generated by OpenCVE AI on September 18, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
Title Command Injection via DELETE in /api/status/data
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T19:04:16.072Z

Reserved: 2026-02-20T13:10:29.716Z

Link: CVE-2026-27560

cve-icon Vulnrichment

Updated: 2026-09-16T19:04:13.120Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:38.977

Modified: 2026-09-16T19:17:13.420

Link: CVE-2026-27560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:15:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')