Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial I/O devices are vulnerable to a local file inclusion attack in their web-based management interface. An attacker with low-level user credentials can exploit this flaw to execute arbitrary PHP code with root privileges, potentially taking complete control of the device and compromising connected industrial systems.
Technical details
CVE-2026-27556 is a PHP local file inclusion (LFI) vulnerability in the /index.php/ajax/save_iodd_parameters endpoint (CWE-98). The vulnerability requires valid operator-level credentials (low privilege) to exploit. An authenticated attacker can manipulate file include parameters to load and execute arbitrary PHP code, achieving remote code execution with root access. The attack is network-reachable and requires no additional user interaction beyond providing valid credentials. Patches are available in firmware version 1.7.4 and later for affected ICE2-* and ICE3-* models.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed: CVE-2026-27556 published