CVE-2026-27559

8.8

Pepperl+Fuchs · IO-Link Master modules (ICE2/ICE3 series)

A command injection vulnerability in the /api/status/data endpoint allows authenticated, low-privileged remote attackers to execute arbitrary commands with root privileges.

Executive summary

A command injection vulnerability in multiple Pepperl+Fuchs IO-Link Master modules permits low-privileged attackers to gain full root-level control over the affected devices.

Vulnerability

The flaw exists in the /api/status/data endpoint, where improper neutralization of special elements allows an authenticated user to perform OS command injection. Because the application runs with elevated permissions, successful exploitation grants the attacker full root access to the underlying operating system.

Business impact

The ability for a low-privileged user to escalate to root privileges poses a critical risk to industrial infrastructure. An attacker could leverage this access to modify device configurations, disrupt industrial processes, or pivot into the internal network, potentially resulting in significant operational downtime and safety hazards. The CVSS score of 8.8 reflects the high confidentiality, integrity, and availability impact of this flaw.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master modules to firmware version 1.7.4 or later as specified in the vendor advisory.

Proactive Monitoring: Review system and access logs for suspicious activity involving the /api/status/data endpoint, particularly requests originating from low-privileged user accounts.

Compensating Controls: Restrict network access to the device management interface to trusted administrative segments only, and implement strict identity and access management controls to limit the number of users with even low-level access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise via root-level command injection, organizations must prioritize patching these devices. Immediate deployment of firmware version 1.7.4 is required to eliminate the command injection vector. Failure to remediate this vulnerability leaves industrial controllers susceptible to full remote takeover by any authenticated user.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.