Search

Find a vulnerability

Search criteria

    191 vulnerabilities by PHOENIX CONTACT

    CVE-2026-27565 (GCVE-0-2026-27565)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:52 – Updated: 2026-09-16 19:03
    VLAI
    Title
    Remote code execution via uploading a malicious IODD file
    Summary
    An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 19:03 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27565",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T19:03:03.181861Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T19:03:09.926Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.\u003c/p\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:52:23.443Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Remote code execution via uploading a malicious IODD file",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27565",
        "datePublished": "2026-09-16T07:52:23.443Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T19:03:09.926Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27564 (GCVE-0-2026-27564)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:52 – Updated: 2026-09-16 18:14
    VLAI
    Title
    Command Injection via PUT in /api/datastorage/data
    Summary
    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:14 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27564",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:14:23.980772Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:14:39.275Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:52:14.929Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection via PUT in /api/datastorage/data",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27564",
        "datePublished": "2026-09-16T07:52:14.929Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T18:14:39.275Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27563 (GCVE-0-2026-27563)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:52 – Updated: 2026-09-18 17:37
    VLAI
    Title
    Command Injection via GET in /api/datastorage/data
    Summary
    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:37 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27563",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:37:01.272893Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:37:15.462Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:52:04.884Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection via GET in /api/datastorage/data",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27563",
        "datePublished": "2026-09-16T07:52:04.884Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-18T17:37:15.462Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27562 (GCVE-0-2026-27562)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:51 – Updated: 2026-09-16 14:53
    VLAI
    Title
    Command Injection via PUT in /api/iodd/config
    Summary
    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 14:53 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27562",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T14:53:22.589910Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T14:53:29.549Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:51:54.116Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection via PUT in /api/iodd/config",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27562",
        "datePublished": "2026-09-16T07:51:54.116Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T14:53:29.549Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27561 (GCVE-0-2026-27561)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:51 – Updated: 2026-09-16 18:36
    VLAI
    Title
    Command Injection via GET in /api/iodd/config
    Summary
    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:21 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27561",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:21:19.534541Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:36:01.493Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:51:34.777Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection via GET in /api/iodd/config",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27561",
        "datePublished": "2026-09-16T07:51:34.777Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T18:36:01.493Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27560 (GCVE-0-2026-27560)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:51 – Updated: 2026-09-16 19:04
    VLAI
    Title
    Command Injection via DELETE in /api/status/data
    Summary
    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 19:04 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27560",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T19:04:08.598951Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T19:04:16.072Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:51:18.570Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection via DELETE in /api/status/data",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27560",
        "datePublished": "2026-09-16T07:51:18.570Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T19:04:16.072Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27559 (GCVE-0-2026-27559)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 18:15
    VLAI
    Title
    Command Injection via GET in /api/status/data
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:15 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27559",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:15:11.790739Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:15:31.190Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:50:58.578Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection via GET in /api/status/data",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27559",
        "datePublished": "2026-09-16T07:50:58.578Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T18:15:31.190Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27558 (GCVE-0-2026-27558)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-18 17:35
    VLAI
    Title
    Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:35 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27558",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:35:37.217450Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:35:51.020Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:50:45.553Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27558",
        "datePublished": "2026-09-16T07:50:45.553Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-18T17:35:51.020Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27557 (GCVE-0-2026-27557)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 15:37
    VLAI
    Title
    Path Traversal in /index.php/view_uploaded_iodd_file
    Summary
    An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 15:34 UTC
    CWE
    • CWE-35 - Path Traversal: '.../...//'
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27557",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T15:34:14.196499Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T15:37:15.109Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server\u0026#x27;s private keys to be read.\u003c/p\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server\u0027s private keys to be read."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-35",
                  "description": "CWE-35 Path Traversal: \u0027.../...//\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:50:32.380Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal in /index.php/view_uploaded_iodd_file",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27557",
        "datePublished": "2026-09-16T07:50:32.380Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T15:37:15.109Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27556 (GCVE-0-2026-27556)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 18:36
    VLAI
    Title
    Local File Inclusion in /index.php/ajax/save_iodd_parameters
    Summary
    A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:21 UTC
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27556",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:21:18.194437Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:36:10.529Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:50:20.465Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Local File Inclusion in /index.php/ajax/save_iodd_parameters",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27556",
        "datePublished": "2026-09-16T07:50:20.465Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T18:36:10.529Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27555 (GCVE-0-2026-27555)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 19:05
    VLAI
    Title
    Local File Inclusion in /index.php/ajax/get_iodd_port_info
    Summary
    A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 19:05 UTC
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27555",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T19:05:09.160663Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T19:05:15.954Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:50:08.560Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Local File Inclusion in /index.php/ajax/get_iodd_port_info",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27555",
        "datePublished": "2026-09-16T07:50:08.560Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T19:05:15.954Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27554 (GCVE-0-2026-27554)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 18:23
    VLAI
    Title
    Command Injection in /index.php/ajax/save_iodd_parameters
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:16 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27554",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:16:33.694487Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:23:49.225Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:49:58.795Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in /index.php/ajax/save_iodd_parameters",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27554",
        "datePublished": "2026-09-16T07:49:58.795Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T18:23:49.225Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27553 (GCVE-0-2026-27553)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-19 02:20
    VLAI
    Title
    Information Disclosure via Schema Path Manipulation
    Summary
    A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:35 UTC
    CWE
    • CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27553",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:35:06.592429Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-19T02:20:02.863Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-497",
                  "description": "CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:49:48.547Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Information Disclosure via Schema Path Manipulation",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27553",
        "datePublished": "2026-09-16T07:49:48.547Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-19T02:20:02.863Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27552 (GCVE-0-2026-27552)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 14:53
    VLAI
    Title
    Unauthorized IODD File Upload due to Improper Authorization
    Summary
    A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 14:53 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27552",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T14:53:40.774542Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T14:53:49.707Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:49:32.300Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Unauthorized IODD File Upload due to Improper Authorization",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27552",
        "datePublished": "2026-09-16T07:49:32.300Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T14:53:49.707Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27551 (GCVE-0-2026-27551)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 18:36
    VLAI
    Title
    Command Injection in /index.php/ajax/parameterManage
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:21 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27551",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:21:16.930249Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:36:16.745Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:49:22.734Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in /index.php/ajax/parameterManage",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27551",
        "datePublished": "2026-09-16T07:49:22.734Z",
        "dateReserved": "2026-02-20T13:10:29.716Z",
        "dateUpdated": "2026-09-16T18:36:16.745Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27550 (GCVE-0-2026-27550)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 19:06
    VLAI
    Title
    Command Injection in Field_Shadow_Password Class
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 19:06 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27550",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T19:06:11.333631Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T19:06:21.541Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:49:12.718Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in Field_Shadow_Password Class",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27550",
        "datePublished": "2026-09-16T07:49:12.718Z",
        "dateReserved": "2026-02-20T13:10:29.715Z",
        "dateUpdated": "2026-09-16T19:06:21.541Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27549 (GCVE-0-2026-27549)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-16 18:25
    VLAI
    Title
    Command Injection in /index.php/attached_devices_tab/do_upload
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:24 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27549",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:24:53.691070Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:25:16.526Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:48:59.523Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in /index.php/attached_devices_tab/do_upload",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27549",
        "datePublished": "2026-09-16T07:48:59.523Z",
        "dateReserved": "2026-02-20T13:10:29.715Z",
        "dateUpdated": "2026-09-16T18:25:16.526Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27548 (GCVE-0-2026-27548)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-18 17:34
    VLAI
    Title
    Command Injection in /index.php/ajax/get_iodd_port_info
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:34 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27548",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:34:24.148955Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:34:40.584Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:48:48.807Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in /index.php/ajax/get_iodd_port_info",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27548",
        "datePublished": "2026-09-16T07:48:48.807Z",
        "dateReserved": "2026-02-20T13:10:29.715Z",
        "dateUpdated": "2026-09-18T17:34:40.584Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27547 (GCVE-0-2026-27547)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-16 14:54
    VLAI
    Title
    Command Injection in /index.php/ajax/get_iodd_menu_info
    Summary
    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 14:54 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27547",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T14:54:02.982738Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T14:54:12.706Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
                }
              ],
              "value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:48:31.955Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in /index.php/ajax/get_iodd_menu_info",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27547",
        "datePublished": "2026-09-16T07:48:31.955Z",
        "dateReserved": "2026-02-20T13:10:29.715Z",
        "dateUpdated": "2026-09-16T14:54:12.706Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-27546 (GCVE-0-2026-27546)

    Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-16 18:36
    VLAI
    Title
    Authentication Bypass in _account_log
    Summary
    An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 18:29 UTC
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    Impacted products
    Vendor Product Version
    Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 PN DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Phoenix Contact IOL MA8 EIP DI8 Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CEI8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CEI8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YL212CPN8M1IO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Carlo Gavazzi Automation YN115CPN8RPIO Affected: 1.0.0 , < 1.7.4 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-27546",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T18:29:20.728448Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T18:36:22.205Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE2-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL1-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-G65L-V1D-Y",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45P-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "ICE3-8IOL-K45S-RJ45",
              "vendor": "Pepperl+Fuchs",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 PN DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "IOL MA8 EIP DI8",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CEI8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CEI8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YL212CPN8M1IO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "YN115CPN8RPIO",
              "vendor": "Carlo Gavazzi Automation",
              "versions": [
                {
                  "lessThan": "1.7.4",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.7.4",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Gabriele Quagliarella from Nozomi Networks"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Luca Borzacchiello from Nozomi Networks"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.\u003c/p\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-288",
                  "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T07:48:15.101Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
            },
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
            "defect": [
              "CERT@VDE#641944"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Authentication Bypass in _account_log",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-27546",
        "datePublished": "2026-09-16T07:48:15.101Z",
        "dateReserved": "2026-02-20T13:10:29.715Z",
        "dateUpdated": "2026-09-16T18:36:22.205Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-41771 (GCVE-0-2025-41771)

    Vulnerability from cvelistv5 – Published: 2026-08-12 08:06 – Updated: 2026-08-12 12:32
    VLAI
    Title
    SQL injection
    Summary
    An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-12 12:31 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Phoenix Contact AXC F 1152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 1252 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 2000 EA Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 2152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 3152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact BPC 9102S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact BPC 9202S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact RFC 4072R Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact RFC 4072S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VL3 UPC 2440 EDGE Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 1000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 2000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 3000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 500 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact Catan C1 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact EPC 1502 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact EPC 1522 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-41771",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-12T12:31:57.783579Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-12T12:32:06.185Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 1152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 1252",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 2000 EA",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 2152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 3152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "BPC 9102S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "BPC 9202S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "RFC 4072R",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "RFC 4072S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VL3 UPC 2440 EDGE",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 1000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 2000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 500",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Catan C1",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EPC 1502",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EPC 1522",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_2000_ea_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:catan_c1_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "CyberDanube"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn authenticated attacker with low privileges can access an endpoint in the controller\u2019s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system\u2019s notification functionality.\u003c/p\u003e"
                }
              ],
              "value": "An authenticated attacker with low privileges can access an endpoint in the controller\u2019s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system\u2019s notification functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T08:06:48.361Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json"
            }
          ],
          "source": {
            "advisory": "VDE-2025-056",
            "defect": [
              "CERT@VDE#641812"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "SQL injection",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2025-41771",
        "datePublished": "2026-08-12T08:06:48.361Z",
        "dateReserved": "2025-04-16T11:18:45.761Z",
        "dateUpdated": "2026-08-12T12:32:06.185Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-41770 (GCVE-0-2025-41770)

    Vulnerability from cvelistv5 – Published: 2026-08-12 08:06 – Updated: 2026-08-12 16:57
    VLAI
    Title
    Unauthenticated Denial of Service
    Summary
    An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-12 16:02 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    Phoenix Contact AXC F 1152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 1252 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 2000 EA Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 2152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 3152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact BPC 9102S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact BPC 9202S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact RFC 4072R Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact RFC 4072S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VL3 UPC 2440 EDGE Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 1000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 2000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 3000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 500 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact Catan C1 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact EPC 1502 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact EPC 1522 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-41770",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-12T16:02:55.318840Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-12T16:57:03.036Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 1152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 1252",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 2000 EA",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 2152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 3152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "BPC 9102S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "BPC 9202S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "RFC 4072R",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "RFC 4072S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VL3 UPC 2440 EDGE",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 1000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 2000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 500",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Catan C1",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EPC 1502",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EPC 1522",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_2000_ea_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:catan_c1_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "CyberDanube"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn unauthenticated denial-of-service vulnerability in the device\u0026#x27;s PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.\u003c/p\u003e"
                }
              ],
              "value": "An unauthenticated denial-of-service vulnerability in the device\u0027s PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770 Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T08:06:26.952Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json"
            }
          ],
          "source": {
            "advisory": "VDE-2025-056",
            "defect": [
              "CERT@VDE#641812"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Unauthenticated Denial of Service",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2025-41770",
        "datePublished": "2026-08-12T08:06:26.952Z",
        "dateReserved": "2025-04-16T11:18:45.761Z",
        "dateUpdated": "2026-08-12T16:57:03.036Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-41769 (GCVE-0-2025-41769)

    Vulnerability from cvelistv5 – Published: 2026-08-12 08:05 – Updated: 2026-08-13 15:39
    VLAI
    Title
    Unauthenticated Buffer Overflow in PROFINET Service
    Summary
    The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 15:39 UTC
    CWE
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    Phoenix Contact AXC F 1152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 1252 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 2152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact AXC F 3152 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact BPC 9102S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact BPC 9202S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact RFC 4072R Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact RFC 4072S Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VL3 UPC 2440 EDGE Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 1000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 2000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 3000 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact VPLCNEXT CONTROL 500 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact EPC 1502 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Phoenix Contact EPC 1522 Affected: 2019.0.4 , < 2026.0.3 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-41769",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T15:39:09.824356Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T15:39:23.555Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 1152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 1252",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 2152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "AXC F 3152",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "BPC 9102S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "BPC 9202S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "RFC 4072R",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "RFC 4072S",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VL3 UPC 2440 EDGE",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 1000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 2000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "VPLCNEXT CONTROL 500",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EPC 1502",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "EPC 1522",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "2026.0.3",
                  "status": "affected",
                  "version": "2019.0.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.0.3",
                      "versionStartIncluding": "2019.0.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "CyberDanube"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe device\u0026#x27;s PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.\u003c/p\u003e"
                }
              ],
              "value": "The device\u0027s PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-120",
                  "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-12T08:05:54.382Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json"
            }
          ],
          "source": {
            "advisory": "VDE-2025-056",
            "defect": [
              "CERT@VDE#641812"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Unauthenticated Buffer Overflow in PROFINET Service",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2025-41769",
        "datePublished": "2026-08-12T08:05:54.382Z",
        "dateReserved": "2025-04-16T11:18:45.761Z",
        "dateUpdated": "2026-08-13T15:39:23.555Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-7849 (GCVE-0-2026-7849)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:54 – Updated: 2026-07-30 14:06
    VLAI
    Title
    Command Injection in SCM (idledisconnect parameter)
    Summary
    Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 14:06 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-7849",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T14:06:34.517268Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T14:06:42.780Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eDue to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.\u003c/p\u003e"
                }
              ],
              "value": "Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:54:03.542Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Command Injection in SCM (idledisconnect parameter)",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-7849",
        "datePublished": "2026-07-30T06:54:03.542Z",
        "dateReserved": "2026-05-05T10:57:27.620Z",
        "dateUpdated": "2026-07-30T14:06:42.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44108 (GCVE-0-2026-44108)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:53 – Updated: 2026-07-30 12:59
    VLAI
    Title
    Firewall bypass during shutdown
    Summary
    Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 12:56 UTC
    CWE
    • CWE-696 - Incorrect Behavior Order
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44108",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T12:56:52.796665Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T12:59:30.573Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eDue to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.\u003c/p\u003e"
                }
              ],
              "value": "Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-696",
                  "description": "CWE-696 Incorrect Behavior Order",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:53:42.718Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Firewall bypass during shutdown",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-44108",
        "datePublished": "2026-07-30T06:53:42.718Z",
        "dateReserved": "2026-05-05T10:48:08.227Z",
        "dateUpdated": "2026-07-30T12:59:30.573Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44107 (GCVE-0-2026-44107)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:53 – Updated: 2026-07-30 15:16
    VLAI
    Title
    Exposed Reboot via Modbus
    Summary
    A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 15:13 UTC
    CWE
    • CWE-749 - Exposed Dangerous Method or Function
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44107",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T15:13:19.629103Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T15:16:52.455Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.\u003c/p\u003e"
                }
              ],
              "value": "A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-749",
                  "description": "CWE-749 Exposed Dangerous Method or Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:53:28.559Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Exposed Reboot via Modbus",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-44107",
        "datePublished": "2026-07-30T06:53:28.559Z",
        "dateReserved": "2026-05-05T10:48:08.227Z",
        "dateUpdated": "2026-07-30T15:16:52.455Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44105 (GCVE-0-2026-44105)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:53 – Updated: 2026-07-30 12:28
    VLAI
    Title
    Cleartext password in logs
    Summary
    The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 12:28 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44105",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T12:28:28.043093Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T12:28:47.946Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe credentials for the local user \u0026quot;user-app\u0026quot; may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user \u0026quot;user-app\u0026quot;. Charging could be interrupted.\u003c/p\u003e"
                }
              ],
              "value": "The credentials for the local user \"user-app\" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user \"user-app\". Charging could be interrupted."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532 Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:53:13.068Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Cleartext password in logs",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-44105",
        "datePublished": "2026-07-30T06:53:13.068Z",
        "dateReserved": "2026-05-05T10:48:08.227Z",
        "dateUpdated": "2026-07-30T12:28:47.946Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44106 (GCVE-0-2026-44106)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:52 – Updated: 2026-07-31 22:47
    VLAI
    Title
    Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file
    Summary
    A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-31 22:47 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44106",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-31T22:47:02.500187Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-31T22:47:27.002Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.\u003c/p\u003e"
                }
              ],
              "value": "A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:52:58.069Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-44106",
        "datePublished": "2026-07-30T06:52:58.069Z",
        "dateReserved": "2026-05-05T10:48:08.227Z",
        "dateUpdated": "2026-07-31T22:47:27.002Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44104 (GCVE-0-2026-44104)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:52 – Updated: 2026-07-30 14:05
    VLAI
    Title
    ControllerAgent does not perform validation of firmware
    Summary
    The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 14:05 UTC
    CWE
    • CWE-347 - Improper Verification of Cryptographic Signature
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44104",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T14:05:30.366585Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T14:05:46.344Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe firmware update process for the basemodule of the charging controller only validates the\nCRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.\u003c/p\u003e"
                }
              ],
              "value": "The firmware update process for the basemodule of the charging controller only validates the\nCRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-347",
                  "description": "CWE-347 Improper Verification of Cryptographic Signature",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:52:31.346Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "ControllerAgent does not perform validation of firmware",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-44104",
        "datePublished": "2026-07-30T06:52:31.346Z",
        "dateReserved": "2026-05-05T10:48:08.226Z",
        "dateUpdated": "2026-07-30T14:05:46.344Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44103 (GCVE-0-2026-44103)

    Vulnerability from cvelistv5 – Published: 2026-07-30 06:52 – Updated: 2026-07-30 12:56
    VLAI
    Title
    JupiCore does not perform validation of firmware
    Summary
    An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-30 12:56 UTC
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    References
    Impacted products
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44103",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-30T12:56:30.769176Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-30T12:56:38.642Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3150",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3100",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3050",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "CHARX SEC-3000",
              "vendor": "Phoenix Contact",
              "versions": [
                {
                  "lessThan": "1.9.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.1",
                      "versionStartIncluding": "1.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ZDI"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.\u003c/p\u003e"
                }
              ],
              "value": "An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-30T06:52:07.531Z",
            "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
            "shortName": "CERTVDE"
          },
          "references": [
            {
              "url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
            }
          ],
          "source": {
            "advisory": "VDE-2026-008",
            "defect": [
              "CERT@VDE#641939"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "JupiCore does not perform validation of firmware",
          "x_generator": {
            "engine": "Vulnogram 0.4.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
        "assignerShortName": "CERTVDE",
        "cveId": "CVE-2026-44103",
        "datePublished": "2026-07-30T06:52:07.531Z",
        "dateReserved": "2026-05-05T10:48:08.226Z",
        "dateUpdated": "2026-07-30T12:56:38.642Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }