CVE-2026-27555
Local File Inclusion in /index.php/ajax/get_iodd_port_info
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
| CWE | CWE-98 |
| Vendor | pepperl+fuchs |
| Product | ice2-8iol1-g65l-v1d |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for pepperl+fuchs ice2-8iol1-g65l-v1d
Be the first to know when new high vulnerabilities affecting pepperl+fuchs ice2-8iol1-g65l-v1d are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Pepperl+Fuchs / ICE2-8IOL1-G65L-V1D
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE2-8IOL-G65L-V1D
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE2-8IOL-K45P-RJ45
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE2-8IOL-K45S-RJ45
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE3-8IOL1-G65L-V1D
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE3-8IOL-G65L-V1D
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE3-8IOL-G65L-V1D-Y
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE3-8IOL-K45P-RJ45
1.0.0 < 1.7.4
Pepperl+Fuchs / ICE3-8IOL-K45S-RJ45
1.0.0 < 1.7.4
Phoenix Contact / IOL MA8 PN DI8
1.0.0 < 1.7.4
Phoenix Contact / IOL MA8 EIP DI8
1.0.0 < 1.7.4
Carlo Gavazzi Automation / YL212CEI8M1IO
1.0.0 < 1.7.4
Carlo Gavazzi Automation / YN115CEI8RPIO
1.0.0 < 1.7.4
Carlo Gavazzi Automation / YL212CPN8M1IO
1.0.0 < 1.7.4
Carlo Gavazzi Automation / YN115CPN8RPIO
1.0.0 < 1.7.4
References
Credits
Gabriele Quagliarella from Nozomi Networks Luca Borzacchiello from Nozomi Networks