CVE-2026-27550

8.8

Pepperl+Fuchs · IO-Link Master devices (ICE2/ICE3 series)

A command injection vulnerability in the Field_Shadow_Password class allows authenticated low-privileged remote attackers to execute arbitrary system commands with root privileges.

Executive summary

A critical command injection vulnerability in multiple Pepperl+Fuchs IO-Link Master devices enables remote attackers with operator credentials to achieve full root-level control.

Vulnerability

This is an OS command injection flaw (CWE-78) located within the Field_Shadow_Password class. A remote attacker with low-level operator privileges can manipulate this class to execute arbitrary commands as the root user.

Business impact

The ability to execute commands with root privileges on industrial networking hardware presents a severe security risk, potentially leading to full device compromise, unauthorized process control, and lateral movement within the operational technology environment. Given the high CVSS score of 8.8, this vulnerability poses a significant threat to system integrity, availability, and the confidentiality of industrial communications.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master units to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Monitor device access logs for suspicious command execution patterns or unauthorized attempts to access the Field_Shadow_Password class.

Compensating Controls: Restrict network access to the management interfaces of these devices to trusted IP addresses only, and enforce strict credential management to minimize the risk of low-privileged accounts being compromised.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates an immediate response. Administrators should verify the firmware versions of all deployed Pepperl+Fuchs ICE2 and ICE3 series modules and prioritize the deployment of the 1.7.4 update to prevent potential remote code execution and full system compromise.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.