Vulnerabilities & Exploits · IoT / OT Attack
Pepperl+Fuchs Gateway Bugs Open OT Bridge Nozomi Networks Labs found 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2 -8IOL-K45P-RJ45 running EtherNet/IP firmware 1.7.3 , including an authentication bypass and multiple command-injection bugs. Pepperl+Fuchs fixed the issues through coordinated disclosure, and CERT@VDE published an advisory; the better-known flaw is CVE-2026-27546 .
The auth bypass can make the web interface treat a normal login attempt like first-time setup, which can hand an attacker an admin session without valid credentials. Other flaws can reach root-level command execution, so compromise is not limited to settings on one box: it can alter IO-Link port configuration, falsify sensor readings, issue actuator commands, or disable the master itself.
That matters because the device sits between field sensors and actuators and higher-level OT systems. In plants that rely on this kind of gateway, a web interface flaw becomes a bridge into process control, and a compromised master can also serve as a pivot deeper into the control stack.
1 source · 5h ago
CVE-2026-27546 NVD KEV
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
CVE-2026-27549 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…
CVE-2026-27559 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…
CVE-2026-27557 NVD KEV
CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…
CVE-2026-27564 NVD KEV
CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…
Timeline Sources Sep 29 Industrial Cyber
Nozomi identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks - Industrial Cyber
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
original Part of the PlainSec briefing for 2026-09-29
Every edition of this story: Pepperl+Fuchs Gateway Bugs Open OT Bridge
More from today
Vulnerabilities & Exploits · IoT / OT Attack
Pepperl+Fuchs Gateway Bugs Open OT Bridge Nozomi Networks Labs found 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2 -8IOL-K45P-RJ45 running EtherNet/IP firmware 1.7.3 , including an authentication bypass and multiple command-injection bugs. Pepperl+Fuchs fixed the issues through coordinated disclosure, and CERT@VDE published an advisory; the better-known flaw is CVE-2026-27546 .
The auth bypass can make the web interface treat a normal login attempt like first-time setup, which can hand an attacker an admin session without valid credentials. Other flaws can reach root-level command execution, so compromise is not limited to settings on one box: it can alter IO-Link port configuration, falsify sensor readings, issue actuator commands, or disable the master itself.
That matters because the device sits between field sensors and actuators and higher-level OT systems. In plants that rely on this kind of gateway, a web interface flaw becomes a bridge into process control, and a compromised master can also serve as a pivot deeper into the control stack.
1 source · 5h ago
CVE-2026-27546 NVD KEV
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
CVE-2026-27549 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…
CVE-2026-27559 NVD KEV
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…
CVE-2026-27557 NVD KEV
CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…
CVE-2026-27564 NVD KEV
CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…
Timeline Sources Sep 29 Industrial Cyber
Nozomi identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks - Industrial Cyber
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
original Part of the PlainSec briefing for 2026-09-29
Every edition of this story: Pepperl+Fuchs Gateway Bugs Open OT Bridge
More from today