Junglewise Threat Intelligence

CVE-2026-27560: Pepperl+Fuchs ICE2/ICE3 command injection in /api/status/data

CVE-2026-27560 · Severity: high · CVSS 7.2 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE2 and ICE3 industrial IO-Link devices contain a command injection flaw in their firmware that allows authenticated attackers to execute arbitrary system commands with root privileges. An attacker with admin credentials can send a crafted DELETE request to the /api/status/data endpoint to run arbitrary code, potentially compromising device integrity, reading sensitive data, or using the device as a foothold in operational technology networks.

Technical details

CVE-2026-27560 is an OS command injection vulnerability (CWE-78) in the /api/status/data endpoint of ICE2/ICE3 firmware versions prior to 1.7.4. The vulnerability requires admin-level authentication and is exploited via a specially crafted DELETE request that injects shell commands into an unvalidated parameter. The injected commands execute with root privileges on the device, allowing full system compromise. Patches are available in firmware version 1.7.4 and later.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4

Timeline

  • 2026-09-16: disclosed

References

Related threats