Phoenixcontact Iol Ma8 Eip Di8 Firmware
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Phoenixcontact Iol Ma8 Eip Di8 Firmware.
By the Year
In 2026 there have been 20 vulnerabilities in Phoenixcontact Iol Ma8 Eip Di8 Firmware with an average score of 8.3 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 20 | 8.29 |
It may take a day or so for new Iol Ma8 Eip Di8 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Phoenixcontact Iol Ma8 Eip Di8 Firmware Security Vulnerabilities
Unauthenticated IODD File Upload in Industrial Automation System
CVE-2026-27565
9.8 - Critical
- September 16, 2026
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Shell injection
Command Injection: /api/datastorage/data (PUT) Root Execution
CVE-2026-27564
7.2 - High
- September 16, 2026
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
Shell injection
Cmd Injection in /api/datastorage/data Allows Root Exec
CVE-2026-27563
7.2 - High
- September 16, 2026
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
Shell injection
Command Injection in /api/iodd/config Allows Root Exec on IoT Device
CVE-2026-27562
7.2 - High
- September 16, 2026
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
Shell injection
Command Injection via /api/iodd/config Enables Root Execution
CVE-2026-27561
7.2 - High
- September 16, 2026
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
Shell injection
Command Injection in IoT Device's /api/status/data Endpoint
CVE-2026-27560
7.2 - High
- September 16, 2026
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
Shell injection
IoT Command Injection via /api/status/data Enabling Root Execution
CVE-2026-27559
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
Shell injection
CVE-2026-27558: PHP CGI Command Injection via /index.php Endpoint
CVE-2026-27558
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.
Shell injection
Path Traversal in /index.php/view_uploaded_iodd_file Exposes SSH Private Keys
CVE-2026-27557
7.5 - High
- September 16, 2026
An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
Path Traversal: '.../...//'
Low-Privileged Remote LFI via /index.php/ajax/save_iodd_parameters (PHP)
CVE-2026-27556
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
Remote file include
LFI in /index.php/ajax/get_iodd_port_info allows PHP code exec
CVE-2026-27555
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
Remote file include
Cmd Injection in /index.php/ajax/save_iodd_parameters (Root Exec)
CVE-2026-27554
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.
Shell injection
CVE-2026-27553: Remote Hash Disclosure via Schema Path Manip in Desktop Central
CVE-2026-27553
6.5 - Medium
- September 16, 2026
A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Improper Authorization Allows IODD Upload on IED Web Interface
CVE-2026-27552
8.1 - High
- September 16, 2026
A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
AuthZ
Command Injection in /index.php/ajax/parameterManage Allows RCE with Root Privileges
CVE-2026-27551
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
Shell injection
Command Injection in Field_Shadow_Password Class Allows Root Exec
CVE-2026-27550
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
Shell injection
Cmd Inject in /index.php/attached_devices_tab/do_upload Enables Root Exec on IoT
CVE-2026-27549
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
Shell injection
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials
CVE-2026-27548
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
Shell injection
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials
CVE-2026-27547
8.8 - High
- September 16, 2026
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.
Shell injection
An unauthenticated remote attacker
CVE-2026-27546
9.8 - Critical
- September 16, 2026
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
Authentication Bypass Using an Alternate Path or Channel
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Phoenixcontact Iol Ma8 Eip Di8 Firmware or by Phoenixcontact? Click the Watch button to subscribe.