CVE-2026-27549
8.8Pepperl+Fuchs · ICE2-8IOL1-G65L-V1D (and related models)
A command injection flaw in the Pepperl+Fuchs device upload endpoint allows authenticated attackers with operator credentials to execute arbitrary commands with root privileges.
Executive summary
A critical command injection vulnerability in Pepperl+Fuchs industrial communication modules allows authenticated attackers to gain full root-level control over the affected devices.
Vulnerability
This vulnerability is an OS Command Injection (CWE-78) located in the /index.php/attached_devices_tab/do_upload endpoint. It requires low-privileged attacker access, specifically valid operator credentials, to trigger the command execution.
Business impact
The ability to execute commands with root privileges on an industrial device represents a severe security risk, potentially leading to complete loss of device integrity, unauthorized process manipulation, or lateral movement within the operational technology environment. With a CVSS score of 8.8, this vulnerability is classified as High and necessitates immediate attention to prevent unauthorized access to critical infrastructure components.
Remediation
Immediate Action: Update all affected Pepperl+Fuchs devices to firmware version 1.7.4 or later immediately.
Proactive Monitoring: Review device access logs for suspicious activity originating from operator-level accounts, particularly requests targeting the upload endpoint.
Compensating Controls: Restrict network access to the device management interface to trusted administrative subnets only, and enforce strict credential management for all operator accounts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for full system compromise, administrators must prioritize patching these devices to version 1.7.4. If immediate patching is not feasible, restrict access to the web management interface to mitigate the risk of an attacker leveraging compromised operator credentials to execute arbitrary system commands.
More Pepperl+Fuchs CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.