Description
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution with root privileges
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a system command injection flaw (CWE-78) that allows an unauthenticated attacker to upload a malicious IODD file. When accepted, the device writes a shell script to its filesystem and executes it with root privileges. The injected script remains active across reboots, providing persistent high‑privilege access to the compromised controller. The result is full compromise of the device, with potential to modify or delete data, inject code, or use the device as part of a botnet.

Affected Systems

Affected vendors are Carlo Gavazzi Automation, Pepperl+Fuchs, and Phoenix Contact. The specific product models included are YL212CEI8M1IO, YL212CPN8M1IO, YN115CEI8RPIO, YN115CPN8RPIO from Carlo Gavazzi; several ICE2 and ICE3 variants from Pepperl+Fuchs such as ICE2‑8IOL‑G65L‑V1D and ICE3‑8IOL‑G65L‑V1D‑Y; and IOL MA8 EIP DI8 and IOL MA8 PN DI8 from Phoenix Contact. No specific firmware or product versions have been supplied in the advisory.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is critical, but its EPSS score of <1% indicates it is rarely exploited in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is the open, unauthenticated IODD upload interface; once a malicious file is accepted, the device automatically writes and runs a root‑privileged script, which persists after reboot. The ease of exploitation means that any exposed controller with this interface is a high‑risk target.

Generated by OpenCVE AI on September 16, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued firmware update that patches the IODD upload flaw.
  • Restrict the IODD upload interface to authorized users only or block it entirely from unauthenticated traffic.
  • Monitor logs for unexpected file upload activity and remove any unauthorized root‑privileged scripts that may have been installed.

Generated by OpenCVE AI on September 16, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Title Remote code execution via uploading a malicious IODD file
First Time appeared Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*
Vendors & Products Carlo Gavazzi
Carlo Gavazzi yl212cei8m1io Firmware
Carlo Gavazzi yl212cpn8m1io Firmware
Carlo Gavazzi yn115cei8rpio Firmware
Carlo Gavazzi yn115cpn8rpio Firmware
Pepperl Fuchs
Pepperl Fuchs ice2 Firmware
Pepperl Fuchs ice3 Firmware
Phoenix Contact
Phoenix Contact iol Ma8 Eip Di8 Firmware
Phoenix Contact iol Ma8 Pn Di8 Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Carlo Gavazzi Yl212cei8m1io Firmware Yl212cpn8m1io Firmware Yn115cei8rpio Firmware Yn115cpn8rpio Firmware
Pepperl Fuchs Ice2 Firmware Ice3 Firmware
Phoenix Contact Iol Ma8 Eip Di8 Firmware Iol Ma8 Pn Di8 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-09-16T19:03:09.926Z

Reserved: 2026-02-20T13:10:29.716Z

Link: CVE-2026-27565

cve-icon Vulnrichment

Updated: 2026-09-16T19:03:06.869Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T08:16:39.740

Modified: 2026-09-16T19:17:14.183

Link: CVE-2026-27565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:15:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')