Impact
A command‑injection flaw exists in the /api/datastorage/data endpoint of certain industrial automation devices. An attacker who authenticates with administrative credentials can craft a specially‑encoded GET request so that the device executes arbitrary shell commands with root privileges. This enables the attacker to take full control of the firmware and any attached instrumentation.
Affected Systems
The vulnerability affects devices from Carlo Gavazzi Automation (models YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (models ICE2‑8IOL‑G65L‑V1D, ICE2‑8IOL‑K45P‑RJ45, ICE2‑8IOL‑K45S‑RJ45, ICE2‑8IOL1‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D, ICE3‑8IOL‑G65L‑V1D‑Y, ICE3‑8IOL‑K45P‑RJ45, ICE3‑8IOL‑K45S‑RJ45, ICE3‑8IOL1‑G65L‑V1D) and Phoenix Contact (IOL MA8 EIP DI8, IOL MA8 PN DI8).
Risk and Exploitability
The CVSS v3 score of 7.2 classifies the issue as high severity, though the EPSS score of 2% suggests a low‑to‑moderate likelihood of exploitation in the near term. Attackers must obtain valid administrative credentials, after which they can send the malicious GET request over the network. Devices exposed to untrusted networks without proper segmentation are thus the most vulnerable. The vulnerability is not listed in the CISA KEV catalog, but the high impact warrants proactive mitigation.
OpenCVE Enrichment