Executive brief
Pepperl+Fuchs ICE2 and ICE3 industrial gateways are affected by multiple critical command injection vulnerabilities in their management API. An attacker with high-privileged access (or via prior authentication bypass) can execute arbitrary commands with root privileges on the device, enabling complete compromise of the gateway's integrity, data theft, and persistent control.
Technical details
The vulnerability is an OS command injection (CWE-78) in the /api/iodd/config REST API endpoint. The flaw exists in parameter handling where user-supplied input is passed unsanitized to shell command execution. An attacker with admin credentials can craft a malicious PUT request containing shell metacharacters to execute arbitrary commands with root privileges. While the reported vulnerability requires valid admin credentials, chaining with CVE-2026-27546 (an unauthenticated authentication bypass) allows complete remote code execution. Firmware versions before 1.7.4 are affected; patched versions are available.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed: Public disclosure via NVD and VDE advisory