CVE-2026-27548 | ICE2-8IOL1-G65L-V1D up to 1.7.3 index.php command injection

SecurityVulns

A vulnerability labeled as very critical has been found in Pepperl+Fuchs/Phoenix Contact/Carlo Gavazzi Automation ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 PN DI8, IOL MA8 EIP DI8, YL212CEI8M1IO, YN115CEI8RPIO, YL212CPN8M1IO and YN115CPN8RPIO up to 1.7.3. Impacted is an unknown function of the file index.php. Executing a manipulation can lead to command injection.

This vulnerability is registered as CVE-2026-27548. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More