Impact
This vulnerability allows a high‑privileged remote attacker to inject and execute arbitrary commands on the device by sending a crafted GET request to the /api/iodd/config endpoint using administrative credentials. The injection flaw grants root‑level execution, of the affected system.
Affected Systems
Affected devices include Carlo Gavazzi Automation units YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO; Pepperl+Fuchs units ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D; and Phoenix Contact IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices, all running the relevant firmware versions.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability, and the EPSS exploitation is somewhat likely but not widespread. While the flaw is not listed in the CISA KEV catalog, it can be abused by attackers who possess or guess administrative credentials or who can otherwise authenticate to the device. Once authenticated, they can craft a malicious GET request to run arbitrary commands with root privileges, potentially taking full control over the device and any connected systems.
OpenCVE Enrichment