Executive brief
Pepperl+Fuchs industrial IO-Link master devices (ICE2 and ICE3 series) contain a command injection vulnerability in the parameter management endpoint. A low-privileged operator can inject shell commands that execute with root privileges, allowing complete compromise of device integrity and potential disruption of industrial operations.
Technical details
The vulnerability is an OS command injection (CWE-78) in the /index.php/ajax/save_iodd_parameters endpoint. It requires valid operator-level credentials to exploit, but allows arbitrary command execution with root privileges on the device. The attack vector is network-based with no user interaction required beyond providing credentials. An authenticated operator can craft malicious payloads in endpoint parameters to break out of command context and execute arbitrary shell commands. Patches are available in firmware version 1.7.4 and later for all affected models.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed