Executive brief
Pepperl+Fuchs industrial IoT gateway devices (ICE2 and ICE3 series) used to manage IO-Link devices in factory automation environments contain multiple critical vulnerabilities. An attacker with administrative credentials can inject arbitrary commands through the /api/datastorage/data endpoint and execute them with root privileges, compromising device integrity and potentially disrupting critical manufacturing operations.
Technical details
This is a command injection vulnerability (CWE-78) in the /api/datastorage/data endpoint accessible via PUT request. The vulnerability requires high-privilege credentials (admin authentication), but allows an authenticated attacker to inject OS commands that execute with root privileges. The root cause is insufficient sanitization of user-supplied input in the datastorage API handler. An attacker can leverage this to achieve remote code execution with the highest system privileges, enabling complete device compromise. Fixes are available in firmware versions 1.7.4 and later for both ICE2-* and ICE3-* product lines.
Affected products
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D <1.7.4
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45 <1.7.4
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D <1.7.4
Timeline
- 2026-09-16: disclosed: Vulnerability published by Pepperl+Fuchs advisory VDE-2026-014