Junglewise Threat Intelligence

CVE-2026-27561: Pepperl+Fuchs ICE2/ICE3 command injection in /api/iodd/config

CVE-2026-27561 · Severity: high · CVSS 7.2 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE3-8IOL-G65L-V1D. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs ICE2 and ICE3 industrial I/O controllers are vulnerable to command injection attacks when admin credentials are presented. An attacker with valid admin login can send a crafted request to execute arbitrary commands with root privileges on the device, potentially compromising production automation systems and the integrity of controlled processes.

Technical details

A command injection vulnerability exists in the /api/iodd/config endpoint of Pepperl+Fuchs ICE2-* and ICE3-* devices running firmware versions prior to 1.7.4. The endpoint fails to properly sanitize input parameters in GET requests, allowing an authenticated admin-level attacker to inject OS commands that execute with root privileges. The attack requires valid admin credentials but no additional user interaction. Successful exploitation allows full device compromise including integrity falsification and persistence across reboots.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D firmware versions <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 firmware versions <1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 firmware versions <1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D firmware versions <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D firmware versions <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y firmware versions <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 firmware versions <1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 firmware versions <1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D firmware versions <1.7.4

Timeline

  • 2026-09-16: disclosed

References

Related threats