Executive brief
Pepperl+Fuchs industrial IO-Link master devices contain multiple command injection vulnerabilities in their web-based management interface. An attacker with administrative credentials can execute arbitrary shell commands with root privileges on the device, allowing them to compromise the integrity of the device and potentially disrupt industrial operations or access sensitive configuration data.
Technical details
The vulnerability is an OS command injection (CWE-78) in the /api/datastorage/data endpoint and multiple other web API endpoints within the device firmware. A high-privileged remote attacker (admin or operator with valid credentials) can craft malicious requests containing shell metacharacters that are improperly sanitized and executed by the underlying system shell. The injected commands execute with root privileges, allowing full system compromise. The affected firmware versions are ICE2-* and ICE3-* prior to 1.7.4. Patches are available in firmware version 1.7.4 and later.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D before 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 before 1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 before 1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D before 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D before 1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y before 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 before 1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 before 1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D before 1.7.4
Timeline
- 2026-09-16: disclosed