Search
Find a vulnerability
Search criteria
191 vulnerabilities by PHOENIX CONTACT
CVE-2026-27565 (GCVE-0-2026-27565)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:52 – Updated: 2026-09-16 19:03
VLAI
EPSS
VEX
Title
Remote code execution via uploading a malicious IODD file
Summary
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 19:03 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27565",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T19:03:03.181861Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:03:09.926Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.\u003c/p\u003e"
}
],
"value": "An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:52:23.443Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Remote code execution via uploading a malicious IODD file",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27565",
"datePublished": "2026-09-16T07:52:23.443Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T19:03:09.926Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27564 (GCVE-0-2026-27564)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:52 – Updated: 2026-09-16 18:14
VLAI
EPSS
VEX
Title
Command Injection via PUT in /api/datastorage/data
Summary
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:14 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27564",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:14:23.980772Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:14:39.275Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:52:14.929Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection via PUT in /api/datastorage/data",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27564",
"datePublished": "2026-09-16T07:52:14.929Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T18:14:39.275Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27563 (GCVE-0-2026-27563)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:52 – Updated: 2026-09-18 17:37
VLAI
EPSS
VEX
Title
Command Injection via GET in /api/datastorage/data
Summary
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:37 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27563",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:37:01.272893Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:37:15.462Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:52:04.884Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection via GET in /api/datastorage/data",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27563",
"datePublished": "2026-09-16T07:52:04.884Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-18T17:37:15.462Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27562 (GCVE-0-2026-27562)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:51 – Updated: 2026-09-16 14:53
VLAI
EPSS
VEX
Title
Command Injection via PUT in /api/iodd/config
Summary
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 14:53 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27562",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:53:22.589910Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:53:29.549Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:51:54.116Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection via PUT in /api/iodd/config",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27562",
"datePublished": "2026-09-16T07:51:54.116Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T14:53:29.549Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27561 (GCVE-0-2026-27561)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:51 – Updated: 2026-09-16 18:36
VLAI
EPSS
VEX
Title
Command Injection via GET in /api/iodd/config
Summary
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:21 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27561",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:21:19.534541Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:36:01.493Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:51:34.777Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection via GET in /api/iodd/config",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27561",
"datePublished": "2026-09-16T07:51:34.777Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T18:36:01.493Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27560 (GCVE-0-2026-27560)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:51 – Updated: 2026-09-16 19:04
VLAI
EPSS
VEX
Title
Command Injection via DELETE in /api/status/data
Summary
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
Severity
7.2 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 19:04 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27560",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T19:04:08.598951Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:04:16.072Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:51:18.570Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection via DELETE in /api/status/data",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27560",
"datePublished": "2026-09-16T07:51:18.570Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T19:04:16.072Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27559 (GCVE-0-2026-27559)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 18:15
VLAI
EPSS
VEX
Title
Command Injection via GET in /api/status/data
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:15 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27559",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:15:11.790739Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:15:31.190Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:50:58.578Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection via GET in /api/status/data",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27559",
"datePublished": "2026-09-16T07:50:58.578Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T18:15:31.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27558 (GCVE-0-2026-27558)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-18 17:35
VLAI
EPSS
VEX
Title
Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:35 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27558",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:35:37.217450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:35:51.020Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:50:45.553Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27558",
"datePublished": "2026-09-16T07:50:45.553Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-18T17:35:51.020Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27557 (GCVE-0-2026-27557)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 15:37
VLAI
EPSS
VEX
Title
Path Traversal in /index.php/view_uploaded_iodd_file
Summary
An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 15:34 UTC
CWE
- CWE-35 - Path Traversal: '.../...//'
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27557",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T15:34:14.196499Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T15:37:15.109Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server\u0026#x27;s private keys to be read.\u003c/p\u003e"
}
],
"value": "An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server\u0027s private keys to be read."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-35",
"description": "CWE-35 Path Traversal: \u0027.../...//\u0027",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:50:32.380Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Path Traversal in /index.php/view_uploaded_iodd_file",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27557",
"datePublished": "2026-09-16T07:50:32.380Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T15:37:15.109Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27556 (GCVE-0-2026-27556)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 18:36
VLAI
EPSS
VEX
Title
Local File Inclusion in /index.php/ajax/save_iodd_parameters
Summary
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:21 UTC
CWE
- CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27556",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:21:18.194437Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:36:10.529Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:50:20.465Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Local File Inclusion in /index.php/ajax/save_iodd_parameters",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27556",
"datePublished": "2026-09-16T07:50:20.465Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T18:36:10.529Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27555 (GCVE-0-2026-27555)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:50 – Updated: 2026-09-16 19:05
VLAI
EPSS
VEX
Title
Local File Inclusion in /index.php/ajax/get_iodd_port_info
Summary
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 19:05 UTC
CWE
- CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27555",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T19:05:09.160663Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:05:15.954Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-98",
"description": "CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:50:08.560Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Local File Inclusion in /index.php/ajax/get_iodd_port_info",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27555",
"datePublished": "2026-09-16T07:50:08.560Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T19:05:15.954Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27554 (GCVE-0-2026-27554)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 18:23
VLAI
EPSS
VEX
Title
Command Injection in /index.php/ajax/save_iodd_parameters
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:16 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27554",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:16:33.694487Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:23:49.225Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:49:58.795Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in /index.php/ajax/save_iodd_parameters",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27554",
"datePublished": "2026-09-16T07:49:58.795Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T18:23:49.225Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27553 (GCVE-0-2026-27553)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-19 02:20
VLAI
EPSS
VEX
Title
Information Disclosure via Schema Path Manipulation
Summary
A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:35 UTC
CWE
- CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27553",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:35:06.592429Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-19T02:20:02.863Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-497",
"description": "CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:49:48.547Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Information Disclosure via Schema Path Manipulation",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27553",
"datePublished": "2026-09-16T07:49:48.547Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-19T02:20:02.863Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27552 (GCVE-0-2026-27552)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 14:53
VLAI
EPSS
VEX
Title
Unauthorized IODD File Upload due to Improper Authorization
Summary
A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 14:53 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27552",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:53:40.774542Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:53:49.707Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:49:32.300Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Unauthorized IODD File Upload due to Improper Authorization",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27552",
"datePublished": "2026-09-16T07:49:32.300Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T14:53:49.707Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27551 (GCVE-0-2026-27551)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 18:36
VLAI
EPSS
VEX
Title
Command Injection in /index.php/ajax/parameterManage
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:21 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27551",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:21:16.930249Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:36:16.745Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:49:22.734Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in /index.php/ajax/parameterManage",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27551",
"datePublished": "2026-09-16T07:49:22.734Z",
"dateReserved": "2026-02-20T13:10:29.716Z",
"dateUpdated": "2026-09-16T18:36:16.745Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27550 (GCVE-0-2026-27550)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:49 – Updated: 2026-09-16 19:06
VLAI
EPSS
VEX
Title
Command Injection in Field_Shadow_Password Class
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 19:06 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27550",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T19:06:11.333631Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:06:21.541Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:49:12.718Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in Field_Shadow_Password Class",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27550",
"datePublished": "2026-09-16T07:49:12.718Z",
"dateReserved": "2026-02-20T13:10:29.715Z",
"dateUpdated": "2026-09-16T19:06:21.541Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27549 (GCVE-0-2026-27549)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-16 18:25
VLAI
EPSS
VEX
Title
Command Injection in /index.php/attached_devices_tab/do_upload
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:24 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27549",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:24:53.691070Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:25:16.526Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:48:59.523Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in /index.php/attached_devices_tab/do_upload",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27549",
"datePublished": "2026-09-16T07:48:59.523Z",
"dateReserved": "2026-02-20T13:10:29.715Z",
"dateUpdated": "2026-09-16T18:25:16.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27548 (GCVE-0-2026-27548)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-18 17:34
VLAI
EPSS
VEX
Title
Command Injection in /index.php/ajax/get_iodd_port_info
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:34 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27548",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:34:24.148955Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:34:40.584Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:48:48.807Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in /index.php/ajax/get_iodd_port_info",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27548",
"datePublished": "2026-09-16T07:48:48.807Z",
"dateReserved": "2026-02-20T13:10:29.715Z",
"dateUpdated": "2026-09-18T17:34:40.584Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27547 (GCVE-0-2026-27547)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-16 14:54
VLAI
EPSS
VEX
Title
Command Injection in /index.php/ajax/get_iodd_menu_info
Summary
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 14:54 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27547",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:54:02.982738Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:54:12.706Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.\u003c/p\u003e"
}
],
"value": "A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:48:31.955Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in /index.php/ajax/get_iodd_menu_info",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27547",
"datePublished": "2026-09-16T07:48:31.955Z",
"dateReserved": "2026-02-20T13:10:29.715Z",
"dateUpdated": "2026-09-16T14:54:12.706Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-27546 (GCVE-0-2026-27546)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:48 – Updated: 2026-09-16 18:36
VLAI
EPSS
VEX
Title
Authentication Bypass in _account_log
Summary
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:29 UTC
CWE
- CWE-288 - Authentication Bypass Using an Alternate Path or Channel
Assigner
References
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 PN DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Phoenix Contact | IOL MA8 EIP DI8 |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CEI8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CEI8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YL212CPN8M1IO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
|
| Carlo Gavazzi Automation | YN115CPN8RPIO |
Affected:
1.0.0 , < 1.7.4
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-27546",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:29:20.728448Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:36:22.205Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE2-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL1-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-G65L-V1D-Y",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45P-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ICE3-8IOL-K45S-RJ45",
"vendor": "Pepperl+Fuchs",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 PN DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "IOL MA8 EIP DI8",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CEI8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CEI8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YL212CPN8M1IO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "YN115CPN8RPIO",
"vendor": "Carlo Gavazzi Automation",
"versions": [
{
"lessThan": "1.7.4",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice2_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pepperl_fuchs:ice3_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_pn_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:iol_ma8_eip_di8_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cei8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cei8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yl212cpn8m1io_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carlo_gavazzi:yn115cpn8rpio_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.7.4",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Gabriele Quagliarella from Nozomi Networks"
},
{
"lang": "en",
"type": "finder",
"value": "Luca Borzacchiello from Nozomi Networks"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.\u003c/p\u003e"
}
],
"value": "An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-288",
"description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:48:15.101Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-014/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-027/"
},
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-028/"
}
],
"source": {
"advisory": "VDE-2026-014, VDE-2026-027, VDE-2026-028",
"defect": [
"CERT@VDE#641944"
],
"discovery": "UNKNOWN"
},
"title": "Authentication Bypass in _account_log",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-27546",
"datePublished": "2026-09-16T07:48:15.101Z",
"dateReserved": "2026-02-20T13:10:29.715Z",
"dateUpdated": "2026-09-16T18:36:22.205Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-41771 (GCVE-0-2025-41771)
Vulnerability from cvelistv5 – Published: 2026-08-12 08:06 – Updated: 2026-08-12 12:32
VLAI
EPSS
VEX
Title
SQL injection
Summary
An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-12 12:31 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
1 reference
Impacted products
17 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | AXC F 1152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 1252 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 2000 EA |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 2152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 3152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | BPC 9102S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | BPC 9202S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | RFC 4072R |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | RFC 4072S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VL3 UPC 2440 EDGE |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 1000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 2000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 3000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 500 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | Catan C1 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | EPC 1502 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | EPC 1522 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-41771",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T12:31:57.783579Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T12:32:06.185Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AXC F 1152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 1252",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 2000 EA",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 2152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 3152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "BPC 9102S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "BPC 9202S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RFC 4072R",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RFC 4072S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VL3 UPC 2440 EDGE",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 1000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 2000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 500",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Catan C1",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EPC 1502",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EPC 1522",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_2000_ea_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:catan_c1_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "CyberDanube"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn authenticated attacker with low privileges can access an endpoint in the controller\u2019s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system\u2019s notification functionality.\u003c/p\u003e"
}
],
"value": "An authenticated attacker with low privileges can access an endpoint in the controller\u2019s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system\u2019s notification functionality."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T08:06:48.361Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json"
}
],
"source": {
"advisory": "VDE-2025-056",
"defect": [
"CERT@VDE#641812"
],
"discovery": "UNKNOWN"
},
"title": "SQL injection",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2025-41771",
"datePublished": "2026-08-12T08:06:48.361Z",
"dateReserved": "2025-04-16T11:18:45.761Z",
"dateUpdated": "2026-08-12T12:32:06.185Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-41770 (GCVE-0-2025-41770)
Vulnerability from cvelistv5 – Published: 2026-08-12 08:06 – Updated: 2026-08-12 16:57
VLAI
EPSS
VEX
Title
Unauthenticated Denial of Service
Summary
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-12 16:02 UTC
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
1 reference
Impacted products
17 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | AXC F 1152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 1252 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 2000 EA |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 2152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 3152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | BPC 9102S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | BPC 9202S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | RFC 4072R |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | RFC 4072S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VL3 UPC 2440 EDGE |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 1000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 2000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 3000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 500 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | Catan C1 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | EPC 1502 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | EPC 1522 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-41770",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T16:02:55.318840Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T16:57:03.036Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AXC F 1152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 1252",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 2000 EA",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 2152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 3152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "BPC 9102S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "BPC 9202S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RFC 4072R",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RFC 4072S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VL3 UPC 2440 EDGE",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 1000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 2000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 500",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Catan C1",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EPC 1502",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EPC 1522",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_2000_ea_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:catan_c1_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "CyberDanube"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn unauthenticated denial-of-service vulnerability in the device\u0026#x27;s PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.\u003c/p\u003e"
}
],
"value": "An unauthenticated denial-of-service vulnerability in the device\u0027s PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T08:06:26.952Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json"
}
],
"source": {
"advisory": "VDE-2025-056",
"defect": [
"CERT@VDE#641812"
],
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Denial of Service",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2025-41770",
"datePublished": "2026-08-12T08:06:26.952Z",
"dateReserved": "2025-04-16T11:18:45.761Z",
"dateUpdated": "2026-08-12T16:57:03.036Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-41769 (GCVE-0-2025-41769)
Vulnerability from cvelistv5 – Published: 2026-08-12 08:05 – Updated: 2026-08-13 15:39
VLAI
EPSS
VEX
Title
Unauthenticated Buffer Overflow in PROFINET Service
Summary
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-13 15:39 UTC
CWE
- CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Assigner
References
1 reference
Impacted products
15 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | AXC F 1152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 1252 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 2152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | AXC F 3152 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | BPC 9102S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | BPC 9202S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | RFC 4072R |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | RFC 4072S |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VL3 UPC 2440 EDGE |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 1000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 2000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 3000 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | VPLCNEXT CONTROL 500 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | EPC 1502 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
|
| Phoenix Contact | EPC 1522 |
Affected:
2019.0.4 , < 2026.0.3
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-41769",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-13T15:39:09.824356Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T15:39:23.555Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AXC F 1152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 1252",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 2152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "AXC F 3152",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "BPC 9102S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "BPC 9202S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RFC 4072R",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RFC 4072S",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VL3 UPC 2440 EDGE",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 1000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 2000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "VPLCNEXT CONTROL 500",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EPC 1502",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "EPC 1522",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "2026.0.3",
"status": "affected",
"version": "2019.0.4",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_1152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_1252_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_2152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:axc_f_3152_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:bpc_9102s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:bpc_9202s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:rfc_4072r_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:rfc_4072s_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vl3_upc_2440_edge_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_1000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_2000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_3000_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:vplcnext_control_500_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:epc_1502_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:epc_1522_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2026.0.3",
"versionStartIncluding": "2019.0.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "CyberDanube"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe device\u0026#x27;s PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.\u003c/p\u003e"
}
],
"value": "The device\u0027s PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-120",
"description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T08:05:54.382Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-056.json"
}
],
"source": {
"advisory": "VDE-2025-056",
"defect": [
"CERT@VDE#641812"
],
"discovery": "UNKNOWN"
},
"title": "Unauthenticated Buffer Overflow in PROFINET Service",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2025-41769",
"datePublished": "2026-08-12T08:05:54.382Z",
"dateReserved": "2025-04-16T11:18:45.761Z",
"dateUpdated": "2026-08-13T15:39:23.555Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-7849 (GCVE-0-2026-7849)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:54 – Updated: 2026-07-30 14:06
VLAI
EPSS
VEX
Title
Command Injection in SCM (idledisconnect parameter)
Summary
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 14:06 UTC
CWE
- CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-7849",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T14:06:34.517268Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T14:06:42.780Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eDue to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.\u003c/p\u003e"
}
],
"value": "Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:54:03.542Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "Command Injection in SCM (idledisconnect parameter)",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-7849",
"datePublished": "2026-07-30T06:54:03.542Z",
"dateReserved": "2026-05-05T10:57:27.620Z",
"dateUpdated": "2026-07-30T14:06:42.780Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-44108 (GCVE-0-2026-44108)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:53 – Updated: 2026-07-30 12:59
VLAI
EPSS
VEX
Title
Firewall bypass during shutdown
Summary
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 12:56 UTC
CWE
- CWE-696 - Incorrect Behavior Order
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44108",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T12:56:52.796665Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T12:59:30.573Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eDue to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.\u003c/p\u003e"
}
],
"value": "Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-696",
"description": "CWE-696 Incorrect Behavior Order",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:53:42.718Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "Firewall bypass during shutdown",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-44108",
"datePublished": "2026-07-30T06:53:42.718Z",
"dateReserved": "2026-05-05T10:48:08.227Z",
"dateUpdated": "2026-07-30T12:59:30.573Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-44107 (GCVE-0-2026-44107)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:53 – Updated: 2026-07-30 15:16
VLAI
EPSS
VEX
Title
Exposed Reboot via Modbus
Summary
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 15:13 UTC
CWE
- CWE-749 - Exposed Dangerous Method or Function
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44107",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T15:13:19.629103Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T15:16:52.455Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.\u003c/p\u003e"
}
],
"value": "A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749 Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:53:28.559Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "Exposed Reboot via Modbus",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-44107",
"datePublished": "2026-07-30T06:53:28.559Z",
"dateReserved": "2026-05-05T10:48:08.227Z",
"dateUpdated": "2026-07-30T15:16:52.455Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-44105 (GCVE-0-2026-44105)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:53 – Updated: 2026-07-30 12:28
VLAI
EPSS
VEX
Title
Cleartext password in logs
Summary
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
Severity
6.6 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 12:28 UTC
CWE
- CWE-532 - Insertion of Sensitive Information into Log File
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44105",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T12:28:28.043093Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T12:28:47.946Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe credentials for the local user \u0026quot;user-app\u0026quot; may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user \u0026quot;user-app\u0026quot;. Charging could be interrupted.\u003c/p\u003e"
}
],
"value": "The credentials for the local user \"user-app\" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user \"user-app\". Charging could be interrupted."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532 Insertion of Sensitive Information into Log File",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:53:13.068Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "Cleartext password in logs",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-44105",
"datePublished": "2026-07-30T06:53:13.068Z",
"dateReserved": "2026-05-05T10:48:08.227Z",
"dateUpdated": "2026-07-30T12:28:47.946Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-44106 (GCVE-0-2026-44106)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:52 – Updated: 2026-07-31 22:47
VLAI
EPSS
VEX
Title
Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file
Summary
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-31 22:47 UTC
CWE
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44106",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-31T22:47:02.500187Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-31T22:47:27.002Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.\u003c/p\u003e"
}
],
"value": "A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:52:58.069Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-44106",
"datePublished": "2026-07-30T06:52:58.069Z",
"dateReserved": "2026-05-05T10:48:08.227Z",
"dateUpdated": "2026-07-31T22:47:27.002Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-44104 (GCVE-0-2026-44104)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:52 – Updated: 2026-07-30 14:05
VLAI
EPSS
VEX
Title
ControllerAgent does not perform validation of firmware
Summary
The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 14:05 UTC
CWE
- CWE-347 - Improper Verification of Cryptographic Signature
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44104",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T14:05:30.366585Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T14:05:46.344Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe firmware update process for the basemodule of the charging controller only validates the\nCRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.\u003c/p\u003e"
}
],
"value": "The firmware update process for the basemodule of the charging controller only validates the\nCRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:52:31.346Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "ControllerAgent does not perform validation of firmware",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-44104",
"datePublished": "2026-07-30T06:52:31.346Z",
"dateReserved": "2026-05-05T10:48:08.226Z",
"dateUpdated": "2026-07-30T14:05:46.344Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-44103 (GCVE-0-2026-44103)
Vulnerability from cvelistv5 – Published: 2026-07-30 06:52 – Updated: 2026-07-30 12:56
VLAI
EPSS
VEX
Title
JupiCore does not perform validation of firmware
Summary
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 12:56 UTC
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Phoenix Contact | CHARX SEC-3150 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3100 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3050 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
|
| Phoenix Contact | CHARX SEC-3000 |
Affected:
1.0.0 , < 1.9.1
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44103",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T12:56:30.769176Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T12:56:38.642Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3150",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3100",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3050",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "CHARX SEC-3000",
"vendor": "Phoenix Contact",
"versions": [
{
"lessThan": "1.9.1",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ZDI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.\u003c/p\u003e"
}
],
"value": "An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T06:52:07.531Z",
"orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"shortName": "CERTVDE"
},
"references": [
{
"url": "https://www.certvde.com/en/advisories/VDE-2026-008/"
}
],
"source": {
"advisory": "VDE-2026-008",
"defect": [
"CERT@VDE#641939"
],
"discovery": "UNKNOWN"
},
"title": "JupiCore does not perform validation of firmware",
"x_generator": {
"engine": "Vulnogram 0.4.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c",
"assignerShortName": "CERTVDE",
"cveId": "CVE-2026-44103",
"datePublished": "2026-07-30T06:52:07.531Z",
"dateReserved": "2026-05-05T10:48:08.226Z",
"dateUpdated": "2026-07-30T12:56:38.642Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}