CVE-2026-27558 | ICE2-8IOL1-G65L-V1D up to 1.7.3 index.php command injection
A vulnerability classified as very critical was found in Pepperl+Fuchs/Phoenix Contact/Carlo Gavazzi Automation ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 PN DI8, IOL MA8 EIP DI8, YL212CEI8M1IO, YN115CEI8RPIO, YL212CPN8M1IO and YN115CPN8RPIO up to 1.7.3. This impacts an unknown function of the file index.php. Such manipulation leads to command injection.
This vulnerability is traded as CVE-2026-27558. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More