CVE-2026-27556
8.8Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)
A local file inclusion vulnerability in the Pepperl+Fuchs IO-Link Master series allows low-privileged remote attackers to execute arbitrary PHP code via the save_iodd_parameters endpoint.
Executive summary
A remote code execution vulnerability in Pepperl+Fuchs IO-Link Master devices poses a severe risk to industrial operations by allowing authenticated attackers to gain full system control.
Vulnerability
This vulnerability is a local file inclusion flaw within the /index.php/ajax/save_iodd_parameters endpoint. An attacker with low-level operator privileges can leverage this endpoint, combined with a valid operator cookie, to execute arbitrary PHP code on the underlying device.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow an attacker to compromise the integrity and availability of industrial control processes, potentially leading to unauthorized system manipulation, production downtime, or the exfiltration of sensitive configuration data.
Remediation
Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master devices to firmware version 1.7.4 or later immediately.
Proactive Monitoring: Review device access logs for suspicious activity targeting the /index.php/ajax/save_iodd_parameters endpoint and monitor for unexpected outbound network connections from the devices.
Compensating Controls: Restrict network access to the management interface of the IO-Link Master devices to trusted subnets only, and implement strict session management to mitigate the risk posed by compromised operator credentials.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution within critical infrastructure components, organizations must prioritize patching these devices to version 1.7.4. Administrators should verify the firmware version of all deployed ICE2 and ICE3 series units and schedule maintenance windows to apply the updates as quickly as possible.
More Pepperl+Fuchs CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.