{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3hioddiodd/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:iodd:iodd:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-27561"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IODD (firmware versions vulnerable to CVE-2026-27561)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-27561 describes a critical command injection vulnerability affecting the IODD device management interface. The vulnerability exists within the /api/iodd/config endpoint, which fails to properly sanitize user-supplied input provided via GET requests. By leveraging existing administrative credentials, a remote attacker can inject arbitrary shell commands that are subsequently executed by the underlying operating system with root privileges. This flaw allows for complete system compromise, including the potential for unauthorized data access, lateral movement within the network, and the installation of persistent backdoors. Defenders should prioritize restricting administrative access to management interfaces and monitor for anomalous HTTP GET requests targeting the configuration API.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full root-level system compromise of the affected IODD device. This vulnerability enables attackers to gain persistent access, exfiltrate sensitive configuration data, and potentially pivot into the internal network infrastructure to which the device is connected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the device management interface to known, trusted administrative subnets.\u003c/li\u003e\n\u003cli\u003eAudit administrative user accounts to ensure credential hygiene and reduce the risk of account compromise.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for GET requests to /api/iodd/config containing unusual query parameters or suspicious shell metacharacters.\u003c/li\u003e\n\u003cli\u003eApply vendor-provided patches or firmware updates addressing CVE-2026-27561 immediately upon availability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T09:50:05Z","date_published":"2026-09-16T09:50:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-27561/","summary":"An authenticated remote attacker with administrative privileges can execute arbitrary commands with root permissions via a crafted GET request to the /api/iodd/config endpoint.","title":"Command Injection Vulnerability in IODD Devices (CVE-2026-27561)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-27561/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:iodd:iodd:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}