Pepperl+Fuchs ICE3-8IOL-K45S-RJ45

20 known vulnerabilities in Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-27565 CVSS 9.8 critical An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The…
  • CVE-2026-27564 CVSS 7.2 high A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT…
  • CVE-2026-27563 CVSS 7.2 high A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted…
  • CVE-2026-27562 CVSS 7.2 high A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT…
  • CVE-2026-27561 CVSS 7.2 high A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET…
  • CVE-2026-27560 CVSS 7.2 high A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted…
  • CVE-2026-27559 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET…
  • CVE-2026-27558 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the…
  • CVE-2026-27557 CVSS 7.5 high An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing…
  • CVE-2026-27556 CVSS 8.8 high A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint…
  • CVE-2026-27555 CVSS 8.8 high A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using…
  • CVE-2026-27554 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using…
  • CVE-2026-27553 CVSS 6.5 medium A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint…
  • CVE-2026-27552 CVSS 8.1 high A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload…
  • CVE-2026-27551 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user…
  • CVE-2026-27550 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator…
  • CVE-2026-27549 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint…
  • CVE-2026-27548 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using…
  • CVE-2026-27547 CVSS 8.8 high A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using…
  • CVE-2026-27546 CVSS 9.8 critical An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when…