Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial I/O devices contain a local file inclusion flaw in their web interface that allows authenticated users to execute arbitrary PHP code with full device privileges. An attacker with valid user credentials can manipulate web requests to include and execute malicious code, potentially taking complete control of the device and compromising critical industrial automation processes.
Technical details
The vulnerability is a PHP local file inclusion (LFI) flaw in the /index.php/ajax/get_iodd_port_info endpoint (CWE-98). The endpoint improperly handles user-supplied input in file include/require statements without sufficient validation or sanitization. An authenticated remote attacker with valid user credentials can exploit this to include arbitrary PHP files and execute code with root privileges on the device. No user interaction is required beyond having valid credentials; the attack is network-accessible. The affected firmware versions are ICE2-* and ICE3-* before 1.7.4. Patches are available in version 1.7.4 and later.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4
Timeline
- 2026-09-16: disclosed: Public disclosure via VDE advisory VDE-2026-014