CVE-2026-27548

Summary

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

Affected Software

VendorProductVersion RangeStatus
Pepperl+FuchsICE2-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D-Y1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 PN DI81.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 EIP DI81.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CEI8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CEI8RPIO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CPN8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CPN8RPIO1.0.0 < 1.7.4affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References