Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial I/O link devices are vulnerable to improper authorization controls on file upload endpoints. An attacker with basic user credentials can upload malicious firmware files that execute with root privileges, potentially hijacking device operations or causing system failures in networked industrial control systems.
Technical details
CVE-2026-27552 is a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint that affects ICE2 and ICE3 firmware versions before 1.7.4. A low-privileged remote attacker with operator credentials can upload a crafted IODD file that contains shell commands executed with root privileges on the device. The vulnerability allows arbitrary code execution even after device reboot. The attack is network-accessible and requires valid operator-level credentials.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed