CVE-2026-27554 | ICE2-8IOL1-G65L-V1D up to 1.7.3 index.php command injection
A vulnerability classified as very critical has been found in Carlo Gavazzi Automation/Pepperl+Fuchs/Phoenix Contact ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 EIP DI8, IOL MA8 PN DI8, YN115CEI8RPIO, YN115CEI8RPIO, YN115CPN8RPIO, YL212CEI8M1IO and YL212CPN8M1IO up to 1.7.3. This affects an unknown function of the file index.php. This manipulation causes command injection.
This vulnerability appears as CVE-2026-27554. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More