Impact
A command injection flaw exists in the /api/datastorage/data endpoint that lets a highly privileged attacker send a crafted PUT request authenticated as an administrator. By exploiting the flaw, the attacker can run arbitrary shell commands with root privileges on the device, which can lead to full compromise of the unit, tampering with functionality and data, and persistence of malicious payloads. The weakness is identified as CWE‑78, reflecting improper handling of system command input.
Affected Systems
Devices from Carlo Gavazzi Automation (models YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO), Pepperl+Fuchs (models ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE2-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D), and Phoenix Contact ( DI8, IOL MA8 PN DI8).
Risk and Exploitability
The CVSS score of 7.2 marks the flaw as high severity, while the EPSS score of 2% suggests a moderate but non‑negligible likelihood of exploitation. The advisory does not list it in the CISA KEV catalog, but attackers could still use the openly requires remote network access to the API and valid administrator credentials, indicating the attack vector is network‑based. Once access is obtained, the attacker can command the device as root, leading to complete compromise.
OpenCVE Enrichment