CVE-2026-27556

8.8

Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)

A local file inclusion vulnerability in the Pepperl+Fuchs IO-Link Master series allows low-privileged remote attackers to execute arbitrary PHP code via the save_iodd_parameters endpoint.

Executive summary

A remote code execution vulnerability in Pepperl+Fuchs IO-Link Master devices poses a severe risk to industrial operations by allowing authenticated attackers to gain full system control.

Vulnerability

This vulnerability is a local file inclusion flaw within the /index.php/ajax/save_iodd_parameters endpoint. An attacker with low-level operator privileges can leverage this endpoint, combined with a valid operator cookie, to execute arbitrary PHP code on the underlying device.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow an attacker to compromise the integrity and availability of industrial control processes, potentially leading to unauthorized system manipulation, production downtime, or the exfiltration of sensitive configuration data.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master devices to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Review device access logs for suspicious activity targeting the /index.php/ajax/save_iodd_parameters endpoint and monitor for unexpected outbound network connections from the devices.

Compensating Controls: Restrict network access to the management interface of the IO-Link Master devices to trusted subnets only, and implement strict session management to mitigate the risk posed by compromised operator credentials.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution within critical infrastructure components, organizations must prioritize patching these devices to version 1.7.4. Administrators should verify the firmware version of all deployed ICE2 and ICE3 series units and schedule maintenance windows to apply the updates as quickly as possible.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.