CVE-2026-27551
8.8Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)
A command injection vulnerability in the parameter management endpoint allows authenticated, low-privileged remote attackers to execute arbitrary commands with root privileges.
Executive summary
A high-severity command injection vulnerability in Pepperl+Fuchs IO-Link Master devices permits authenticated attackers to achieve full root-level system compromise.
Vulnerability
This is an OS Command Injection (CWE-78) vulnerability located in the /index.php/ajax/parameterManage endpoint. A low-privileged authenticated user can inject malicious commands that the system executes with root-level privileges.
Business impact
The ability to execute commands as root allows an attacker to take complete control of the affected industrial communication hardware. This poses significant risks to operational technology environments, including potential data exfiltration, unauthorized process manipulation, or permanent system disruption. Given the CVSS score of 8.8, this vulnerability represents a severe threat to operational continuity and integrity.
Remediation
Immediate Action: Update all affected Pepperl+Fuchs ICE2 and ICE3 IO-Link Master devices to firmware version 1.7.4 or later.
Proactive Monitoring: Review system access logs for unusual activity originating from low-privileged service accounts or unexpected calls to the /index.php/ajax/parameterManage endpoint.
Compensating Controls: Restrict network access to the management interface of the IO-Link devices to authorized administrative subnets only, effectively limiting the attack surface for remote exploitation.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of command injection flaws that result in root-level execution, organizations should prioritize the deployment of the 1.7.4 firmware update. Administrators must verify the current firmware version across all deployed ICE2 and ICE3 units and schedule maintenance windows to ensure these devices are updated immediately, thereby neutralizing the risk of unauthorized system takeover.
More Pepperl+Fuchs CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.