Description
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
Published: 2026-09-16
Score: 7.2 High
EPSS: 2.2% Low
KEV: No
Impact: Remote Command Execution (root)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows a high‑privileged remote attacker to inject and execute arbitrary commands on the device by sending a crafted GET request to the /api/iodd/config endpoint using administrative credentials. The injection flaw grants root‑level execution, of the affected system.

Affected Systems

Affected devices include Carlo Gavazzi Automation units YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO; Pepperl+Fuchs units ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D; and Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices, all running the relevant firmware versions.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability, and the EPSS exploitation is somewhat likely but not widespread. While the flaw is not listed in the CISA KEV catalog, it can be abused by attackers who possess or guess administrative credentials or who can otherwise authenticate to the device. Once authenticated, they can craft a malicious GET request to run arbitrary commands with root privileges, potentially taking full control over the device and any connected systems.

Generated by OpenCVE AI on September 16, 2026 at 14:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware on all affected devices to the vendor‑released version that resolves the command injection flaw.
  • If a patch is not yet available, block or restrict external network access to the /api/iodd/config endpoint, enforce strong authentication, and limit GET permissions to administrators only.
  • Implement strict input validation and sanitization for all parameters received by the API to prevent command injection, following the guidance for CWE‑78 weaknessesous GET requests or unexpected command executions and set up alerts to detect attempted exploitation.

Generated by OpenCVE AI on September 16, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
Title Command Injection via GET in /api/iodd/config
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T18:36:01.493Z

Reserved: 2026-02-20T13:10:29.716Z

Link: CVE-2026-27561

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:21.268Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:39.133

Modified: 2026-09-16T19:17:13.633

Link: CVE-2026-27561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:00:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')