Executive brief
Pepperl+Fuchs ICE2 and ICE3 Industrial Ethernet Controllers are vulnerable to command injection in their web management interface. An attacker with low-level user credentials can inject malicious commands that execute with root privileges, potentially compromising device integrity and enabling unauthorized control of industrial equipment.
Technical details
This vulnerability is an OS command injection flaw (CWE-78) in the /index.php/ajax/parameterManage endpoint. A low-privileged remote attacker with valid user credentials can inject arbitrary shell commands into endpoint parameters, which are then executed with root privileges on the device. The attack requires network access and valid user authentication but no user interaction. An attacker can achieve full system compromise including code execution, data exfiltration, and persistent backdoor installation. Patches are available in firmware version 1.7.4 and later.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed
- 2026-09-16: advisory: VDE-2026-014 advisory published