CVE-2026-27555
8.8Pepperl+Fuchs · IO-Link Master modules (ICE2/ICE3 series)
A local file inclusion vulnerability in the IO-Link Master modules allows low-privileged authenticated attackers to execute arbitrary PHP code via the get_iodd_port_info endpoint.
Executive summary
A high-severity local file inclusion vulnerability in Pepperl+Fuchs IO-Link Master devices allows authenticated remote attackers to achieve arbitrary code execution.
Vulnerability
The device is vulnerable to a local file inclusion flaw within the /index.php/ajax/get_iodd_port_info endpoint. An attacker with low-level user credentials can leverage a valid user cookie to manipulate input parameters, resulting in the execution of arbitrary PHP code on the underlying system.
Business impact
A successful exploit allows for full system compromise, granting the attacker the ability to execute commands with the privileges of the web server. Given the nature of these industrial devices, this could lead to unauthorized control over connected sensors or actuators, resulting in significant operational downtime or the manipulation of critical industrial processes. The CVSS score of 8.8 reflects the high potential for impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update all affected ICE2 and ICE3 series modules to firmware version 1.7.4 or later immediately.
Proactive Monitoring: Monitor device access logs for unusual requests directed at the /index.php/ajax/get_iodd_port_info endpoint or attempts to inject directory traversal sequences into web parameters.
Compensating Controls: Restrict network access to the device management interface to trusted administrative subnets and enforce strict session management to minimize the risk of unauthorized cookie usage.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The vulnerability poses a substantial risk to industrial operational environments. Administrators must prioritize the deployment of the 1.7.4 firmware update across all vulnerable Pepperl+Fuchs IO-Link Master modules to eliminate the code execution vector. Failure to patch these devices leaves the industrial control loop susceptible to unauthorized interference and potential physical process disruption.
More Pepperl+Fuchs CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.