CVE-2026-27547

8.8

Pepperl+Fuchs · ICE2/ICE3 IO-Link Master series

A command injection vulnerability in the IO-Link Master devices allows authenticated users with low privileges to execute arbitrary commands with root privileges via the get_iodd_menu_info endpoint.

Executive summary

A critical command injection vulnerability in Pepperl+Fuchs IO-Link Master devices allows authenticated attackers to achieve full root-level control over the hardware.

Vulnerability

The device is susceptible to OS command injection (CWE-78) within the /index.php/ajax/get_iodd_menu_info endpoint. An attacker possessing valid user or operator credentials can trigger this flaw to execute system commands with root privileges.

Business impact

Successful exploitation grants an attacker full root access to the industrial communication device, which can lead to complete system compromise, unauthorized manipulation of industrial processes, or total loss of device availability. With a CVSS score of 8.8, this vulnerability represents a high-severity risk to operational technology environments, as it allows lateral movement and potential disruption of connected production infrastructure.

Remediation

Immediate Action: Update all affected ICE2 and ICE3 IO-Link Master devices to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Review access logs for suspicious requests directed at the /index.php/ajax/get_iodd_menu_info endpoint and monitor for unusual process execution patterns originating from the web server user.

Compensating Controls: Restrict network access to the management interface of the IO-Link devices to authorized administrative subnets only, and employ a Web Application Firewall to filter malicious input strings directed at the device web server.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the high CVSS score and the potential for full administrative takeover of industrial hardware, this vulnerability poses a significant threat to operational integrity. IT and OT security teams should prioritize the firmware update to version 1.7.4 across all deployed units to eliminate the command injection vector and prevent unauthorized root execution.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.