CVE-2026-27550
8.8Pepperl+Fuchs · IO-Link Master devices (ICE2/ICE3 series)
A command injection vulnerability in the Field_Shadow_Password class allows authenticated low-privileged remote attackers to execute arbitrary system commands with root privileges.
Executive summary
A critical command injection vulnerability in multiple Pepperl+Fuchs IO-Link Master devices enables remote attackers with operator credentials to achieve full root-level control.
Vulnerability
This is an OS command injection flaw (CWE-78) located within the Field_Shadow_Password class. A remote attacker with low-level operator privileges can manipulate this class to execute arbitrary commands as the root user.
Business impact
The ability to execute commands with root privileges on industrial networking hardware presents a severe security risk, potentially leading to full device compromise, unauthorized process control, and lateral movement within the operational technology environment. Given the high CVSS score of 8.8, this vulnerability poses a significant threat to system integrity, availability, and the confidentiality of industrial communications.
Remediation
Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master units to firmware version 1.7.4 or later immediately.
Proactive Monitoring: Monitor device access logs for suspicious command execution patterns or unauthorized attempts to access the Field_Shadow_Password class.
Compensating Controls: Restrict network access to the management interfaces of these devices to trusted IP addresses only, and enforce strict credential management to minimize the risk of low-privileged accounts being compromised.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates an immediate response. Administrators should verify the firmware versions of all deployed Pepperl+Fuchs ICE2 and ICE3 series modules and prioritize the deployment of the 1.7.4 update to prevent potential remote code execution and full system compromise.
More Pepperl+Fuchs CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.