CVE-2026-27558

8.8

Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)

A command injection vulnerability in the Pepperl+Fuchs IO-Link Master allows an authenticated low-privileged attacker to execute arbitrary commands with root privileges via the web interface.

Executive summary

A critical command injection vulnerability in Pepperl+Fuchs IO-Link Master devices allows authenticated attackers to gain full root-level control over the system.

Vulnerability

The vulnerability is an OS Command Injection (CWE-78) located in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint. It requires an attacker to possess valid operator-level credentials, after which they can inject malicious commands that execute with root privileges.

Business impact

The ability to execute commands with root privileges grants an attacker complete control over the affected industrial hardware. This risk is severe, as it could lead to unauthorized modification of industrial processes, complete loss of device availability, or use of the device as a pivot point within the operational technology network. With a CVSS score of 8.8, this vulnerability represents a high-risk scenario that necessitates immediate attention to prevent operational disruption.

Remediation

Immediate Action: Update the firmware for all affected ICE2 and ICE3 series devices to version 1.7.4 or later immediately.

Proactive Monitoring: Monitor network traffic and device logs for suspicious activity targeting the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint.

Compensating Controls: Restrict access to the web interface to authorized management networks only and ensure that operator credentials are managed securely, following the principle of least privilege.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for full system compromise and the high CVSS severity rating, organizations must prioritize the deployment of firmware version 1.7.4 across their fleet of Pepperl+Fuchs IO-Link devices. If an immediate update is not feasible, restrict administrative access to the management interface to prevent unauthorized users from reaching the vulnerable endpoint. Failure to patch these devices leaves the industrial control environment highly susceptible to malicious command execution.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.