Junglewise Threat Intelligence

CVE-2026-27546: Pepperl+Fuchs ICE2/ICE3 firmware authentication bypass in _account_log

CVE-2026-27546 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE2 and ICE3 industrial I/O Link devices contain a flaw in their authentication mechanism that allows unauthenticated attackers to log in with administrator privileges without valid credentials. An attacker can gain full control of these devices used in factory automation and industrial control systems, potentially disrupting production lines and accessing sensitive operational data.

Technical details

The vulnerability is an authentication bypass (CWE-288) in the _account_log function that allows unauthenticated remote attackers to gain administrative access. No authentication credentials or preconditions are required; the flaw can be exploited directly over the network. An attacker can achieve complete compromise of the device with administrator privileges, enabling device control, configuration changes, and potential lateral movement into industrial control networks. Patches are available in firmware version 1.7.4 and later.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: advisory: VDE-2026-014 advisory published

References

Related threats