CVE-2026-27548

8.8

Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)

A command injection vulnerability in the Pepperl+Fuchs IO-Link Master series allows authenticated attackers to execute arbitrary code with root privileges.

Executive summary

A command injection vulnerability in Pepperl+Fuchs IO-Link Master devices allows low-privileged authenticated attackers to gain full root-level control over the system.

Vulnerability

This is a command injection flaw (CWE-78) located in the /index.php/ajax/get_iodd_port_info endpoint. An attacker with standard user or operator credentials can inject OS commands that execute with root privileges on the device.

Business impact

The ability to execute commands as root allows an attacker to achieve complete system compromise, potentially leading to unauthorized data exfiltration, permanent denial of service, or the use of the device as a pivot point within the industrial control network. Given the CVSS score of 8.8, this vulnerability represents a high-risk scenario for operational technology environments where device integrity is critical for safety and process availability.

Remediation

Immediate Action: Update all affected ICE2 and ICE3 IO-Link Master units to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Monitor device access logs for suspicious activity targeting the /index.php/ajax/get_iodd_port_info endpoint, particularly requests originating from non-administrative accounts.

Compensating Controls: Implement strict network segmentation to limit access to the device management interface to authorized personnel only, and utilize a Web Application Firewall to block requests containing malicious command patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of command injection vulnerabilities in industrial hardware, immediate firmware remediation is required. Organizations should prioritize updating all affected Pepperl+Fuchs devices to version 1.7.4 to eliminate the risk of unauthorized root-level access and potential lateral movement within the production environment.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.