Junglewise Threat Intelligence

CVE-2026-27551: Pepperl+Fuchs ICE2/ICE3 command injection in parameterManage

CVE-2026-27551 · Severity: high · CVSS 8.8 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE2 and ICE3 Industrial Ethernet Controllers are vulnerable to command injection in their web management interface. An attacker with low-level user credentials can inject malicious commands that execute with root privileges, potentially compromising device integrity and enabling unauthorized control of industrial equipment.

Technical details

This vulnerability is an OS command injection flaw (CWE-78) in the /index.php/ajax/parameterManage endpoint. A low-privileged remote attacker with valid user credentials can inject arbitrary shell commands into endpoint parameters, which are then executed with root privileges on the device. The attack requires network access and valid user authentication but no user interaction. An attacker can achieve full system compromise including code execution, data exfiltration, and persistent backdoor installation. Patches are available in firmware version 1.7.4 and later.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: advisory: VDE-2026-014 advisory published

References

Related threats