CVE-2026-27546
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
Vulnerabilities · 4h ago
Nozomi Networks Labs found 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45 running EtherNet/IP firmware 1.7.3, including an authentication bypass and multiple command-injection bugs. Pepperl+Fuchs fixed the issues through coordinated disclosure, and CERT@VDE published an advisory; the better-known flaw is CVE-2026-27546.
The auth bypass can make the web interface treat a normal login attempt like first-time setup, which can hand an attacker an admin session without valid credentials. Other flaws can reach root-level command execution, so compromise is not limited to settings on one box: it can alter IO-Link port configuration, falsify sensor readings, issue actuator commands, or disable the master itself.
That matters because the device sits between field sensors and actuators and higher-level OT systems. In plants that rely on this kind of gateway, a web interface flaw becomes a bridge into process control, and a compromised master can also serve as a pivot deeper into the control stack.
CVSS 9.8 CRITICAL: an unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an…
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the…
CVSS 8.8 HIGH: a low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by…
CVSS 7.5 HIGH: an unauthenticated remote attacker can exploit a path traversal vulnerability in the…
CVSS 7.2 HIGH: a high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint…
1 source covering this story
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
Part of the PlainSec briefing for 2026-09-29