CVE-2026-27556
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
- Published Sep 16, 2026
- CVSS 8.8 high
- 0.9% chance of exploitation in the next 30 days (EPSS)
Affected software
- Carlo Gavazzi Automation YL212CEI8M1IO
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D
- Phoenix Contact IOL MA8 EIP DI8
- Phoenix Contact IOL MA8 PN DI8