CVE-2026-27565

9.8

Pepperl+Fuchs · IO-Link Master series (ICE2/ICE3)

An unauthenticated remote attacker can upload a malicious IODD file to execute arbitrary shell commands with root privileges, resulting in persistent compromise.

Executive summary

A critical OS command injection vulnerability in Pepperl+Fuchs IO-Link Master devices allows unauthenticated remote attackers to achieve full system control with root privileges.

Vulnerability

This is an OS command injection vulnerability (CWE-78) triggered by the improper neutralization of special elements during the upload of IODD files. An unauthenticated remote attacker can leverage this flaw to execute arbitrary shell scripts with root-level permissions that persist across system reboots.

Business impact

The exploitation of this vulnerability carries a severe risk to operational technology environments. With a CVSS score of 9.8, this flaw facilitates complete system compromise, potentially leading to unauthorized control over industrial processes, data exfiltration, and permanent denial of service. Such an impact could result in significant safety risks, production downtime, and major operational disruption.

Remediation

Immediate Action: Update all affected Pepperl+Fuchs IO-Link Master units (ICE2 and ICE3 series) to firmware version 1.7.4 or later immediately.

Proactive Monitoring: Monitor network traffic for unusual file upload requests to IO-Link configuration interfaces and inspect system logs for unauthorized shell command execution or unexpected persistence mechanisms.

Compensating Controls: Implement strict network segmentation to isolate industrial control devices from untrusted networks and utilize a Web Application Firewall or industrial firewall to restrict access to the device management interface to authorized IP addresses only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity of this vulnerability and the potential for persistent, unauthenticated root access, administrators must prioritize the firmware update to version 1.7.4. If immediate patching is not feasible, restrict network access to the affected devices to mitigate the risk of remote exploitation until the update can be applied.

More Pepperl+Fuchs CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Gabriele Quagliarella from Nozomi Networks, Luca Borzacchiello from Nozomi Networks, per the CVE Program record.