CVE-2026-27551

8.8

Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)

A command injection vulnerability in the parameter management endpoint allows authenticated, low-privileged remote attackers to execute arbitrary commands with root privileges.

Executive summary

A high-severity command injection vulnerability in Pepperl+Fuchs IO-Link Master devices permits authenticated attackers to achieve full root-level system compromise.

Vulnerability

This is an OS Command Injection (CWE-78) vulnerability located in the /index.php/ajax/parameterManage endpoint. A low-privileged authenticated user can inject malicious commands that the system executes with root-level privileges.

Business impact

The ability to execute commands as root allows an attacker to take complete control of the affected industrial communication hardware. This poses significant risks to operational technology environments, including potential data exfiltration, unauthorized process manipulation, or permanent system disruption. Given the CVSS score of 8.8, this vulnerability represents a severe threat to operational continuity and integrity.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs ICE2 and ICE3 IO-Link Master devices to firmware version 1.7.4 or later.

Proactive Monitoring: Review system access logs for unusual activity originating from low-privileged service accounts or unexpected calls to the /index.php/ajax/parameterManage endpoint.

Compensating Controls: Restrict network access to the management interface of the IO-Link devices to authorized administrative subnets only, effectively limiting the attack surface for remote exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of command injection flaws that result in root-level execution, organizations should prioritize the deployment of the 1.7.4 firmware update. Administrators must verify the current firmware version across all deployed ICE2 and ICE3 units and schedule maintenance windows to ensure these devices are updated immediately, thereby neutralizing the risk of unauthorized system takeover.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.