CVE-2026-27562
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
- Published Sep 16, 2026
- CVSS 7.2 high
- 2.7% chance of exploitation in the next 30 days (EPSS)
Affected software
- Carlo Gavazzi Automation YL212CEI8M1IO
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D
- Phoenix Contact IOL MA8 EIP DI8
- Phoenix Contact IOL MA8 PN DI8