CVE-2026-27565: Carlo Gavazzi Automation YL212CEI8M1IO
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Affected products
- Carlo Gavazzi Automation YL212CEI8M1IO: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Carlo Gavazzi Automation YL212CPN8M1IO: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Carlo Gavazzi Automation YN115CEI8RPIO: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Carlo Gavazzi Automation YN115CPN8RPIO: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE2-8iol-g65l-v1d: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE2-8iol-k45p-RJ45: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE2-8iol-k45s-RJ45: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE2-8iol1-g65l-v1d: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE3-8iol-g65l-v1d: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE3-8iol-g65l-v1d-Y: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE3-8iol-k45p-RJ45: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE3-8iol-k45s-RJ45: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Pepperl+fuchs ICE3-8iol1-g65l-v1d: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Phoenix Contact Iol MA8 Eip DI8: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
- Phoenix Contact Iol MA8 Pn DI8: from 1.0.0, before 1.7.4 (fixed in 1.7.4)
Published 2026-09-16. Last modified 2026-09-16.