CVE-2026-27549 | ICE2-8IOL1-G65L-V1D up to 1.7.3 index.php command injection

SecurityVulns

A vulnerability described as very critical has been identified in Carlo Gavazzi Automation/Pepperl+Fuchs/Phoenix Contact ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 PN DI8, IOL MA8 EIP DI8, YL212CEI8M1IO, YN115CEI8RPIO, YL212CPN8M1IO and YN115CPN8RPIO up to 1.7.3. The impacted element is an unknown function of the file index.php. The manipulation results in command injection.

This vulnerability is reported as CVE-2026-27549. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More