CVE-2026-27556 | ICE2-8IOL1-G65L-V1D up to 1.7.3 Ajax save_iodd_parameters operator file inclusion
A vulnerability was found in Pepperl+Fuchs/Phoenix Contact/Carlo Gavazzi Automation ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 PN DI8, IOL MA8 EIP DI8, YL212CEI8M1IO, YN115CEI8RPIO, YL212CPN8M1IO and YN115CPN8RPIO up to 1.7.3 and classified as critical. This affects an unknown part of the file /index.php/ajax/save_iodd_parameters of the component Ajax. The manipulation of the argument operator results in file inclusion.
This vulnerability was named CVE-2026-27556. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More