CVE-2026-27547 | ICE2-8IOL1-G65L-V1D up to 1.7.3 index.php command injection

SecurityVulns

A vulnerability identified as very critical has been detected in Pepperl+Fuchs/Phoenix Contact/Carlo Gavazzi Automation ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45, IOL MA8 PN DI8, IOL MA8 EIP DI8, YL212CEI8M1IO, YN115CEI8RPIO, YL212CPN8M1IO and YN115CPN8RPIO up to 1.7.3. This issue affects some unknown processing of the file index.php. Performing a manipulation results in command injection.

This vulnerability is cataloged as CVE-2026-27547. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More