CVE-2026-27546

9.8

Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)

An authentication bypass vulnerability in the _account_log function allows unauthenticated remote attackers to gain administrative access to affected Pepperl+Fuchs IO-Link Master devices.

Executive summary

A critical authentication bypass in Pepperl+Fuchs IO-Link Master devices allows unauthenticated remote attackers to achieve full administrative control over the hardware.

Vulnerability

The flaw exists within the _account_log function, which fails to correctly validate user credentials. An unauthenticated remote attacker can leverage this alternate path to bypass authentication and log in with administrative privileges.

Business impact

Successful exploitation of this vulnerability results in a total compromise of the affected IO-Link Master devices. Given the CVSS score of 9.8, the risk is critical, as attackers can alter operational configurations, intercept industrial process data, or disable safety-critical monitoring, leading to significant operational downtime and potential physical process interference.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master devices to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Review device access logs for unauthorized administrative login events or anomalous patterns originating from unknown or external network segments.

Compensating Controls: Isolate industrial control devices from the public internet and restrict management access to authorized internal networks via firewall rules to minimize exposure.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with its ease of exploitation from a remote, unauthenticated state, necessitates immediate action. Security teams must prioritize the deployment of the 1.7.4 firmware update across all identified infrastructure to prevent unauthorized administrative access and maintain the integrity of industrial control operations.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.