Junglewise Threat Intelligence

CVE-2026-27563: Pepperl+Fuchs ICE2 and ICE3 command injection in datastorage endpoint

CVE-2026-27563 · Severity: high · CVSS 7.2 · Published 2026-09-16

Technologies: Pepperl+Fuchs ICE2-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-G65L-V1D, Pepperl+Fuchs ICE3-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y, Pepperl+Fuchs ICE2-8IOL-K45S-RJ45, Pepperl+Fuchs ICE3-8IOL-K45S-RJ45, Pepperl+Fuchs ICE2-8IOL-K45P-RJ45, Pepperl+Fuchs ICE2-8IOL1-G65L-V1D, Pepperl+Fuchs ICE3-8IOL-K45P-RJ45. Vendors: Pepperl+Fuchs.

Executive brief

Pepperl+Fuchs industrial IO-Link master devices contain multiple command injection vulnerabilities in their web-based management interface. An attacker with administrative credentials can execute arbitrary shell commands with root privileges on the device, allowing them to compromise the integrity of the device and potentially disrupt industrial operations or access sensitive configuration data.

Technical details

The vulnerability is an OS command injection (CWE-78) in the /api/datastorage/data endpoint and multiple other web API endpoints within the device firmware. A high-privileged remote attacker (admin or operator with valid credentials) can craft malicious requests containing shell metacharacters that are improperly sanitized and executed by the underlying system shell. The injected commands execute with root privileges, allowing full system compromise. The affected firmware versions are ICE2-* and ICE3-* prior to 1.7.4. Patches are available in firmware version 1.7.4 and later.

Affected products

  • Pepperl+Fuchs ICE2-8IOL-G65L-V1D before 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 before 1.7.4
  • Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 before 1.7.4
  • Pepperl+Fuchs ICE2-8IOL1-G65L-V1D before 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D before 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y before 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 before 1.7.4
  • Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 before 1.7.4
  • Pepperl+Fuchs ICE3-8IOL1-G65L-V1D before 1.7.4

Timeline

  • 2026-09-16: disclosed

References

Related threats