Executive brief
Pepperl+Fuchs industrial I/O devices (ICE2 and ICE3 series) contain a command injection flaw in their web interface that allows a user with standard credentials to execute arbitrary commands with root-level privileges. An attacker with legitimate operator or user credentials can compromise device integrity, access sensitive data, or disrupt critical industrial control operations.
Technical details
The /index.php/ajax/get_iodd_port_info endpoint in Pepperl+Fuchs ICE2 and ICE3 devices contains an OS command injection vulnerability (CWE-78) due to improper input validation. An authenticated attacker with low-privileged user or operator credentials can inject shell metacharacters into endpoint parameters to break out of intended command context and execute arbitrary shell commands. The vulnerability requires valid authentication (PR:L) but no user interaction, runs over the network, and allows execution of commands with root privileges, resulting in complete system compromise. Patched firmware versions 1.7.4 and later are available.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D Firmware ICE2-* < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 Firmware ICE2-* < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 Firmware ICE2-* < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D Firmware ICE2-* < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D Firmware ICE3-* < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y Firmware ICE3-* < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 Firmware ICE3-* < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 Firmware ICE3-* < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D Firmware ICE3-* < 1.7.4
Timeline
- 2026-09-16: disclosed