CVE-2026-27549

8.8

Pepperl+Fuchs · ICE2-8IOL1-G65L-V1D (and related models)

A command injection flaw in the Pepperl+Fuchs device upload endpoint allows authenticated attackers with operator credentials to execute arbitrary commands with root privileges.

Executive summary

A critical command injection vulnerability in Pepperl+Fuchs industrial communication modules allows authenticated attackers to gain full root-level control over the affected devices.

Vulnerability

This vulnerability is an OS Command Injection (CWE-78) located in the /index.php/attached_devices_tab/do_upload endpoint. It requires low-privileged attacker access, specifically valid operator credentials, to trigger the command execution.

Business impact

The ability to execute commands with root privileges on an industrial device represents a severe security risk, potentially leading to complete loss of device integrity, unauthorized process manipulation, or lateral movement within the operational technology environment. With a CVSS score of 8.8, this vulnerability is classified as High and necessitates immediate attention to prevent unauthorized access to critical infrastructure components.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs devices to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Review device access logs for suspicious activity originating from operator-level accounts, particularly requests targeting the upload endpoint.

Compensating Controls: Restrict network access to the device management interface to trusted administrative subnets only, and enforce strict credential management for all operator accounts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for full system compromise, administrators must prioritize patching these devices to version 1.7.4. If immediate patching is not feasible, restrict access to the web management interface to mitigate the risk of an attacker leveraging compromised operator credentials to execute arbitrary system commands.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.