CVE-2026-27547: Command Injection in /index.php/ajax/get_iodd_menu_info
Published Sep 16, 2026
·Updated
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/getioddmenuinfo endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.
Affected Software
1 affected component
/index.php/ajax/get_iodd_menu_info
Event History
Sep 16, 2026
CVE Published
via MITRE·07:48 AM
Data Sourced
via MITRE·07:48 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be able to reach the endpoint remotely and authenticate with valid user or operator credentials. No user interaction is required.
2
What is the likely impact if exploitation succeeds?
Successful exploitation allows execution of commands with root privileges on the affected device. This can compromise confidentiality, integrity, and availability.
3
Are unauthenticated attackers affected by this vulnerability?
The available information states that valid user or operator credentials are required. It does not describe unauthenticated exploitation.