An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE2-8IOL-G65L-V1D | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE2-8IOL-K45P-RJ45 | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE2-8IOL-K45S-RJ45 | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE3-8IOL1-G65L-V1D | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE3-8IOL-G65L-V1D-Y | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE3-8IOL-K45P-RJ45 | 1.0.0 ~ 1.7.4 | - |
|
| Pepperl+Fuchs | ICE3-8IOL-K45S-RJ45 | 1.0.0 ~ 1.7.4 | - |
|
| Phoenix Contact | IOL MA8 PN DI8 | 1.0.0 ~ 1.7.4 | - |
|
| Phoenix Contact | IOL MA8 EIP DI8 | 1.0.0 ~ 1.7.4 | - |
|
| Carlo Gavazzi Automation | YL212CEI8M1IO | 1.0.0 ~ 1.7.4 | - |
|
| Carlo Gavazzi Automation | YN115CEI8RPIO | 1.0.0 ~ 1.7.4 | - |
|
| Carlo Gavazzi Automation | YL212CPN8M1IO | 1.0.0 ~ 1.7.4 | - |
|
| Carlo Gavazzi Automation | YN115CPN8RPIO | 1.0.0 ~ 1.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27565 | 9.8 CRITICAL | Remote code execution via uploading a malicious IODD file |
| CVE-2026-27550 | 8.8 HIGH | Command Injection in Field_Shadow_Password Class |
| CVE-2026-27559 | 8.8 HIGH | Command Injection via GET in /api/status/data |
| CVE-2026-27549 | 8.8 HIGH | Command Injection in /index.php/attached_devices_tab/do_upload |
| CVE-2026-27555 | 8.8 HIGH | Local File Inclusion in /index.php/ajax/get_iodd_port_info |
| CVE-2026-27548 | 8.8 HIGH | Command Injection in /index.php/ajax/get_iodd_port_info |
| CVE-2026-27551 | 8.8 HIGH | Command Injection in /index.php/ajax/parameterManage |
| CVE-2026-27556 | 8.8 HIGH | Local File Inclusion in /index.php/ajax/save_iodd_parameters |
| CVE-2026-27554 | 8.8 HIGH | Command Injection in /index.php/ajax/save_iodd_parameters |
| CVE-2026-27547 | 8.8 HIGH | Command Injection in /index.php/ajax/get_iodd_menu_info |
| CVE-2026-27558 | 8.8 HIGH | Command Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files |
| CVE-2026-27552 | 8.1 HIGH | Unauthorized IODD File Upload due to Improper Authorization |
| CVE-2026-27557 | 7.5 HIGH | Path Traversal in /index.php/view_uploaded_iodd_file |
| CVE-2026-27560 | 7.2 HIGH | Command Injection via DELETE in /api/status/data |
| CVE-2026-27562 | 7.2 HIGH | Command Injection via PUT in /api/iodd/config |
| CVE-2026-27564 | 7.2 HIGH | Command Injection via PUT in /api/datastorage/data |
| CVE-2026-27563 | 7.2 HIGH | Command Injection via GET in /api/datastorage/data |
| CVE-2026-27561 | 7.2 HIGH | Command Injection via GET in /api/iodd/config |
| CVE-2026-27553 | 6.5 MEDIUM | Information Disclosure via Schema Path Manipulation |
No comments yet