Junglewise Threat Intelligence

CVE-2026-27549: Pepperl+Fuchs ICE firmware command injection in attached_devices_tab

CVE-2026-27549 · Severity: high · CVSS 8.8 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE device firmware contains a command injection flaw in the file upload endpoint that allows authenticated operators to execute arbitrary system commands with root privileges. An attacker with operator credentials can inject malicious commands during file uploads, gaining complete control over the device and potentially compromising industrial automation systems that rely on these controllers.

Technical details

A command injection vulnerability exists in the /index.php/attached_devices_tab/do_upload endpoint where user-supplied input is not properly sanitized before being passed to OS-level commands. The vulnerability requires valid operator-level credentials to exploit but allows unauthenticated privilege escalation to root. An authenticated operator can craft a malicious upload request containing shell metacharacters that are executed with the highest system privileges. The affected versions are ICE2-* and ICE3-* firmware prior to 1.7.4, and a patch is available in version 1.7.4 or later.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4

Timeline

  • 2026-09-16: disclosed: CVE-2026-27549 published

References

Related threats