CVE-2026-27562

Summary

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

Affected Software

VendorProductVersion RangeStatus
Pepperl+FuchsICE2-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE2-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL1-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-G65L-V1D-Y1.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45P-RJ451.0.0 < 1.7.4affected
Pepperl+FuchsICE3-8IOL-K45S-RJ451.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 PN DI81.0.0 < 1.7.4affected
Phoenix ContactIOL MA8 EIP DI81.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CEI8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CEI8RPIO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYL212CPN8M1IO1.0.0 < 1.7.4affected
Carlo Gavazzi AutomationYN115CPN8RPIO1.0.0 < 1.7.4affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References