Summary
The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.
Impact
Authentication can be bypassed. Code with high access rights can be executed on the device so that the integrity of the device can be falsified. Sensitive information can be read out.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| 70104877 | ICE2-8IOL-G65L-V1D | Firmware ICE2-* <1.7.4 |
| 70108831, 70195316 | ICE2-8IOL-K45P-RJ45 | Firmware ICE2-* <1.7.4 |
| 70104879, 70195318 | ICE2-8IOL-K45S-RJ45 | Firmware ICE2-* <1.7.4 |
| 70118644 | ICE2-8IOL1-G65L-V1D | Firmware ICE2-* <1.7.4 |
| 70104876, 70129287 | ICE3-8IOL-G65L-V1D | Firmware ICE3-* <1.7.4 |
| 70133474 | ICE3-8IOL-G65L-V1D-Y | Firmware ICE3-* <1.7.4 |
| 70108832, 70195319 | ICE3-8IOL-K45P-RJ45 | Firmware ICE3-* <1.7.4 |
| 70104878, 70195322 | ICE3-8IOL-K45S-RJ45 | Firmware ICE3-* <1.7.4 |
| 70118645 | ICE3-8IOL1-G65L-V1D | Firmware ICE3-* <1.7.4 |
Vulnerabilities
Expand / Collapse allAn unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.
Mitigation
- Minimize network exposure for affected products and ensure that they are not accessible via the Internet.
- Isolate affected products from the corporate network.
- If remote access is required, use secure methods such as virtual private networks(VPNs).
Remediation
Install the firmware update 1.7.8.
Acknowledgments
Pepperl+Fuchs SE thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- Gabriele Quagliarella, Luca Borzacchiello from Nozomi Networks for reporting (see https://nozominetworks.com/ )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 09/16/2026 10:00 | Initial release. |