Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial IO-Link devices contain a command injection flaw in their firmware that allows authenticated attackers to execute arbitrary system commands with root privileges. An attacker with admin credentials can send a crafted DELETE request to the /api/status/data endpoint to run arbitrary code, potentially compromising device integrity, reading sensitive data, or using the device as a foothold in operational technology networks.
Technical details
CVE-2026-27560 is an OS command injection vulnerability (CWE-78) in the /api/status/data endpoint of ICE2/ICE3 firmware versions prior to 1.7.4. The vulnerability requires admin-level authentication and is exploited via a specially crafted DELETE request that injects shell commands into an unvalidated parameter. The injected commands execute with root privileges on the device, allowing full system compromise. Patches are available in firmware version 1.7.4 and later.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 < 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D < 1.7.4
Timeline
- 2026-09-16: disclosed