Full Report
Researchers from Nozomi Networks Labs identified 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45 running EtherNet/IP firmware version... The post Nozomi identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks appeared first on Industrial Cyber.
Analysis Summary
# Vulnerability: Critical Remote Root Access in Pepperl+Fuchs IO-Link Master
## CVE Details
* **CVE ID:** CVE-2026-27546 (Primary focus), plus 18 additional vulnerabilities.
* **CVSS Score:** Not explicitly listed in text, but categorized as critical due to remote root access and authentication bypass.
* **CWE:** Logic flaw in authentication (Authentication Bypass), OS Command Injection.
## Affected Systems
* **Products:** Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45.
* **Versions:** EtherNet/IP firmware version 1.7.3.
* **Configurations:** Devices running the HTTPS-based management interface and/or CGI-based REST API endpoints.
## Vulnerability Description
Researchers identified 19 security flaws, the most critical being a logic flaw in the initial password setup function (CVE-2026-27546). Under specific conditions, the WebUI incorrectly identifies an unauthenticated login attempt as a first-time configuration event, allowing an attacker to bypass credentials and obtain an administrative session.
Additionally, several OS command injection vulnerabilities were found in the PHP-based WebUI and CGI-based REST API. Because these components run with **root privileges**, any successful exploitation results in full system compromise.
## Exploitation
* **Status:** PoC developed by Nozomi Networks; coordinated disclosure completed. No reports of active exploitation in the wild at the time of the report.
* **Complexity:** Low (Authentication bypass relies on specific logic conditions).
* **Attack Vector:** Network (Remote via HTTPS/WebUI).
## Impact
* **Confidentiality:** High (Full access to device configuration and sensitive industrial data).
* **Integrity:** High (Ability to manipulate sensor readings, inject commands to actuators, and modify IODD files).
* **Availability:** High (Attacker can disable the IO-Link master or disrupt field-level operations).
* **OT Specific Impact:** Allows pivoting from the management network to the industrial control network (EtherNet/IP, Modbus TCP, OPC UA, MQTT).
## Remediation
### Patches
* Pepperl+Fuchs has released updated firmware to address these flaws. Users should refer to the **CERT@VDE** advisory for specific download instructions and fixed version numbers.
### Workarounds
* Restrict access to the HTTPS management interface to authorized management networks only.
* Disable unused services (e.g., MQTT, OPC UA) if not required for operations.
* Ensure the device is placed behind a managed industrial firewall.
## Detection
* **Indicators of Compromise:** Unusual administrative logins originating from unexpected IP addresses; unauthorized changes to IO-Link port configurations or IODD file uploads.
* **Detection Methods:** Monitor network traffic for anomalous calls to `/index.php/` or `/api/` paths; audit device logs for "first-time configuration" triggers on already deployed devices.
## References
* **Vendor Advisory:** CERT@VDE (Specific link not provided in text).
* **Nozomi Networks Research:** hxxps[://]www[.]nozominetworks[.]com/blog/fooling-the-master-pepperl-fuchs-io-link-under-attack
* **Industrial Cyber Article:** hxxps[://]industrialcyber[.]co/threats-attacks/nozomi-identifies-19-vulnerabilities-in-pepperl-fuchs-io-link-master-enabling-root-access-and-ot-attacks/