Executive brief
Pepperl+Fuchs industrial Ethernet I/O Link master devices used in factory automation are vulnerable to command injection attacks. An attacker with low-level user credentials can execute arbitrary commands with root privileges on the device, allowing complete compromise of the device's integrity and control.
Technical details
CVE-2026-27558 is a command injection vulnerability (CWE-78) in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint. A low-privileged remote attacker with valid operator credentials can inject OS commands that are executed with root privileges on the device. The vulnerability requires authentication (operator-level credentials) and network reachability to the device's web interface. Successful exploitation allows an attacker to execute arbitrary shell commands with the highest privileges, leading to complete device compromise. Firmware versions below 1.7.4 for ICE2-* and ICE3-* product lines are affected.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4
Timeline
- 2026-09-16: disclosed: CVE-2026-27558 disclosed