CVE-2026-27554
8.8Pepperl+Fuchs · IO-Link Master modules (ICE2/ICE3 series)
A command injection vulnerability in the Pepperl+Fuchs IO-Link Master modules allows authenticated attackers to execute arbitrary commands with root privileges via the save_iodd_parameters endpoint.
Executive summary
A critical command injection vulnerability in Pepperl+Fuchs IO-Link Master modules allows low-privileged authenticated users to gain full root control over the affected devices.
Vulnerability
This is an OS command injection flaw (CWE-78) located in the /index.php/ajax/save_iodd_parameters endpoint. The vulnerability can be triggered by any authenticated operator, allowing the execution of system commands with root privileges.
Business impact
Successful exploitation of this vulnerability grants an attacker complete control over the industrial communication device. Because the commands execute with root privileges, the attacker could potentially pivot into the broader industrial control network, exfiltrate sensitive configuration data, or disrupt critical manufacturing processes. With a CVSS score of 8.8, this vulnerability represents a high risk to operational continuity and system integrity.
Remediation
Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master modules to firmware version 1.7.4 or later as specified in the vendor advisory.
Proactive Monitoring: Review device access logs for suspicious activity involving the /index.php/ajax/save_iodd_parameters endpoint and monitor for unexpected process execution originating from the web interface.
Compensating Controls: Restrict network access to the device management interface to trusted administrative subnets only, and implement strict account management policies to limit the number of users with operator-level access.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The ability for a low-privileged user to escalate to root access on an industrial device is a severe security failure that necessitates immediate attention. Organizations utilizing Pepperl+Fuchs ICE2 and ICE3 series modules must prioritize the deployment of firmware version 1.7.4 to eliminate this command injection vector. Failure to patch these devices leaves critical infrastructure vulnerable to unauthorized control and potential operational sabotage.
More Pepperl+Fuchs CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.