Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial input/output devices contain multiple critical vulnerabilities in their web management interface. An attacker without authentication can read sensitive files including SSH private keys, bypass authentication entirely, and execute arbitrary code with root privileges on affected devices. This could allow attackers to steal credentials, disable critical industrial equipment, or pivot into connected networks.
Technical details
CVE-2026-27557 is a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint that allows unauthenticated remote attackers to read arbitrary files from the device filesystem, including SSH private keys. The vulnerability stems from insufficient input validation on file path parameters. An attacker can leverage directory traversal sequences (e.g., ../) to navigate outside intended directories and access sensitive configuration files and cryptographic material. No authentication is required to exploit this flaw, making it immediately exploitable by any network-adjacent attacker. Patches are available in firmware version 1.7.4 and later.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D firmware < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 firmware < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 firmware < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D firmware < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D firmware < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y firmware < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 firmware < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 firmware < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D firmware < 1.7.4
Timeline
- 2026-09-16: disclosed: Published by VDE-2026-014