CVE-2026-27551 | ICE2-8IOL1-G65L-V1D up to 1.7.3 parameterManage index.php command injection

SecurityVulns

A vulnerability, which was classified as very critical, has been found in Carlo Gavazzi Automation/Pepperl+Fuchs/Phoenix Contact ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 EIP DI8, IOL MA8 PN DI8, YN115CEI8RPIO, YN115CPN8RPIO, YL212CEI8M1IO and YL212CPN8M1IO up to 1.7.3. Affected is an unknown function of the file index.php of the component parameterManage. Performing a manipulation results in command injection.

This vulnerability is known as CVE-2026-27551. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More