Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial control devices are affected by a command injection vulnerability in their web management interface. An attacker with low-level user credentials can execute arbitrary commands with root privileges on the device, potentially compromising device integrity, data confidentiality, and operational availability in critical industrial settings.
Technical details
The vulnerability is an OS command injection flaw (CWE-78) in the /index.php/ajax/get_iodd_menu_info endpoint. A low-privileged remote attacker who holds valid user or operator credentials can inject shell commands into a parameter processed by this endpoint without proper sanitization, resulting in arbitrary code execution with root privileges. The attack requires network access and valid authentication credentials but no user interaction. Patches are available in firmware version 1.7.4 and later for affected ICE2 and ICE3 models.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4
Timeline
- 2026-09-16: disclosed: CVE-2026-27547 published