Back to overview

Pepperl+Fuchs: Multiple vulnerabilites in Comtrol IO-Link Master

VDE-2020-038
Last update
05/14/2025 15:00
Published at
01/04/2021 14:01
Vendor(s)
Pepperl+Fuchs SE
External ID
VDE-2020-038
CSAF Document

Summary

Several vulnerabilities exist within firmware versions up to and including v1.5.48.

Impact

Pepperl+Fuchs analyzed and identified affected devices.
Remote attackers may exploit multiple vulnerabilities to get access to the device and
execute any program and tap information.

Affected Product(s)

Model no. Product name Affected versions
IO-Link Master 4-EIP Firmware <=v1.5.48
IO-Link Master 4-PNIO Firmware <=v1.5.48
IO-Link Master 8-EIP Firmware <=v1.5.48
IO-Link Master 8-EIP-L Firmware <=v1.5.48
IO-Link Master 8-PNIO Firmware <=v1.5.48
IO-Link Master 8-PNIO-L Firmware <=v1.5.48
IO-Link Master DR-8-EIP Firmware <=v1.5.48
IO-Link Master DR-8-EIP-P Firmware <=v1.5.48
IO-Link Master DR-8-EIP-T Firmware <=v1.5.48
IO-Link Master DR-8-PNIO Firmware <=v1.5.48
IO-Link Master DR-8-PNIO-P Firmware <=v1.5.48
IO-Link Master DR-8-PNIO-T Firmware <=v1.5.48

Vulnerabilities

Expand / Collapse all

Published
09/22/2025 14:58
Weakness
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
References

Published
09/22/2025 14:58
Weakness
Cross-Site Request Forgery (CSRF) (CWE-352)
References

Published
09/22/2025 14:58
Weakness
Improper Validation of Specified Quantity in Input (CWE-1284)
References

Published
09/22/2025 14:58
Weakness
Out-of-bounds Read (CWE-125)
References

Published
09/22/2025 14:58
Weakness
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
References

Published
09/22/2025 14:58
Weakness
NULL Pointer Dereference (CWE-476)
References

Remediation

In order to prevent the exploitation of the reported vulnerabilities, we recommend that the
affected units be updated with the following three firmware packages:

  • U-Boot bootloader version 1.36

  • System image version 1.52

  • Application base version 1.6.11

Revision History

Version Date Summary
1 01/04/2021 14:01 initial revision
2 02/12/2025 17:57 Fix: corrected self-reference, fixed version
3 05/14/2025 15:00 Fix: added distribution