Vulnerabilities · 4h ago

Pepperl+Fuchs Gateway Bugs Open OT Bridge

Nozomi Networks Labs found 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45 running EtherNet/IP firmware 1.7.3, including an authentication bypass and multiple command-injection bugs. Pepperl+Fuchs fixed the issues through coordinated disclosure, and CERT@VDE published an advisory; the better-known flaw is CVE-2026-27546.

The auth bypass can make the web interface treat a normal login attempt like first-time setup, which can hand an attacker an admin session without valid credentials. Other flaws can reach root-level command execution, so compromise is not limited to settings on one box: it can alter IO-Link port configuration, falsify sensor readings, issue actuator commands, or disable the master itself.

That matters because the device sits between field sensors and actuators and higher-level OT systems. In plants that rely on this kind of gateway, a web interface flaw becomes a bridge into process control, and a compromised master can also serve as a pivot deeper into the control stack.

CVE-2026-27546

NVD KEV

CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…

CVE-2026-27549

NVD KEV

CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…

CVE-2026-27559

NVD KEV

CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…

CVE-2026-27557

NVD KEV

CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…

CVE-2026-27564

NVD KEV

CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-29

Editions

Related stories