Junglewise Threat Intelligence

CVE-2026-27552: Pepperl+Fuchs ICE2/ICE3 improper authorization in IODD upload

CVE-2026-27552 · Severity: high · CVSS 8.1 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE2 and ICE3 industrial I/O link devices are vulnerable to improper authorization controls on file upload endpoints. An attacker with basic user credentials can upload malicious firmware files that execute with root privileges, potentially hijacking device operations or causing system failures in networked industrial control systems.

Technical details

CVE-2026-27552 is a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint that affects ICE2 and ICE3 firmware versions before 1.7.4. A low-privileged remote attacker with operator credentials can upload a crafted IODD file that contains shell commands executed with root privileges on the device. The vulnerability allows arbitrary code execution even after device reboot. The attack is network-accessible and requires valid operator-level credentials.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4

Timeline

  • 2026-09-16: disclosed

References

Related threats