Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial I/O controllers are vulnerable to command injection attacks when admin credentials are presented. An attacker with valid admin login can send a crafted request to execute arbitrary commands with root privileges on the device, potentially compromising production automation systems and the integrity of controlled processes.
Technical details
A command injection vulnerability exists in the /api/iodd/config endpoint of Pepperl+Fuchs ICE2-* and ICE3-* devices running firmware versions prior to 1.7.4. The endpoint fails to properly sanitize input parameters in GET requests, allowing an authenticated admin-level attacker to inject OS commands that execute with root privileges. The attack requires valid admin credentials but no additional user interaction. Successful exploitation allows full device compromise including integrity falsification and persistence across reboots.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D firmware versions <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 firmware versions <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 firmware versions <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D firmware versions <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D firmware versions <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y firmware versions <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 firmware versions <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 firmware versions <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D firmware versions <1.7.4
Timeline
- 2026-09-16: disclosed