Unauthorized IODD File Upload due to Improper Authorization
Published Sep 16, 2026
8.1
HIGHCVSS 3.1
EPSS 0.60%
Description
A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
Affected products
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
-
Affected
- ≥ 1.0.0, < 1.7.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Carlo Gavazzi Automation | Yl212cei8m1io | unaffected | Affected
|
| Carlo Gavazzi Automation | Yl212cpn8m1io | unaffected | Affected
|
| Carlo Gavazzi Automation | Yn115cei8rpio | unaffected | Affected
|
| Carlo Gavazzi Automation | Yn115cpn8rpio | unaffected | Affected
|
| Pepperl+Fuchs | Ice2-8iol-G65l-V1d | unaffected | Affected
|
| Pepperl+Fuchs | Ice2-8iol-K45p-Rj45 | unaffected | Affected
|
| Pepperl+Fuchs | Ice2-8iol-K45s-Rj45 | unaffected | Affected
|
| Pepperl+Fuchs | Ice2-8iol1-G65l-V1d | unaffected | Affected
|
| Pepperl+Fuchs | Ice3-8iol-G65l-V1d | unaffected | Affected
|
| Pepperl+Fuchs | Ice3-8iol-G65l-V1d-Y | unaffected | Affected
|
| Pepperl+Fuchs | Ice3-8iol-K45p-Rj45 | unaffected | Affected
|
| Pepperl+Fuchs | Ice3-8iol-K45s-Rj45 | unaffected | Affected
|
| Pepperl+Fuchs | Ice3-8iol1-G65l-V1d | unaffected | Affected
|
| Phoenix Contact | Iol Ma8 Eip Di8 | unaffected | Affected
|
| Phoenix Contact | Iol Ma8 PN Di8 | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data