CVE-2026-27557
An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
- Published Sep 16, 2026
- CVSS 7.5 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
Affected software
- Carlo Gavazzi Automation YL212CEI8M1IO
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D
- Phoenix Contact IOL MA8 EIP DI8
- Phoenix Contact IOL MA8 PN DI8