CVE-2026-27555: Local File Inclusion in /index.php/ajax/get_iodd_port_info
Published Sep 16, 2026
·Updated
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/getioddportinfo endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
Event History
Sep 16, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs a valid user cookie, so exploitation requires authenticated access as a low-privileged user. No user interaction is required after the attacker has that cookie.
2
What is the likely impact if exploitation succeeds?
Successful exploitation can allow arbitrary PHP code execution on the affected device. The provided severity vector indicates high confidentiality, integrity, and availability impact.