Impact
The flaw is a command injection in the /api/iodd/config endpoint. A high‑privileged remote attacker can craft a PUT request with valid admin credentials to execute arbitrary commands with root authority on the device, giving full control over the firmware and the associated protected infrastructure.
Affected Systems
The vulnerability affects devices from Carlo Gavazzi Automation (YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D) and Phoenix Contact (IOL MA8 EIP DI8, IOL MA8 PN DI8). Firmware version information is not specified, so all firmware in these lines that still contain the embedded API may be impacted until a vendor revision is applied.
Risk and Exploitability
The CVSS score of 7.2 signals a high severity vulnerability. An EPSS value of 2% suggests a moderate likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers must first authenticate with administrator credentials, but once authenticated they can run commands as root, jeopardizing device integrity, confidentiality and availability. The most probable attack vector involves a remote network connection to the device’s API, so devices exposed to external networks or lacking proper segmentation are at greatest risk.
OpenCVE Enrichment