Skip to content
Critical Vulnerabilities Found in Pepperl+Fuchs IO-Link Master

Critical Vulnerabilities Found in Pepperl+Fuchs IO-Link Master

First seen 29 Sep 2026, 15:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 16:22 UTC
  • •19 vulnerabilities identified in Pepperl+Fuchs IO-Link Master.
  • •Critical authentication bypass allows admin access without credentials.
  • •Vulnerabilities could disrupt industrial automation processes.

Nozomi Networks Labs discovered 19 vulnerabilities in the Pepperl+Fuchs IO-Link Master ICE2-8IOL-K45P-RJ45, including a critical authentication bypass (CVE-2026-27546) that allows attackers to gain admin access without credentials. The device, integral to industrial automation, connects sensors and actuators to control systems, making it a significant target. Other vulnerabilities include OS command injection flaws that can execute commands with root privileges. These flaws could disrupt operations by altering sensor readings or actuator commands. Pepperl+Fuchs has addressed the vulnerabilities through coordinated disclosure, and CERT@VDE has published an advisory. The affected firmware version is EtherNet/IP 1.7.3. Users are advised to review the findings and apply mitigations promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-16
CVE-2026-27546 published
A critical authentication bypass vulnerability was disclosed, allowing unauthorized admin access.
Industrialcyber.Co
2026-09-16
Multiple CVEs published
Eight vulnerabilities including CVE-2026-27562 and CVE-2026-27559 were disclosed, affecting the IO-Link Master.
Industrialcyber.Co
2026-09-16
CVE-2026-27562 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-27559 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-27549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-27557 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-27561 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-27560 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-27564 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
Vulnerabilities disclosed
Nozomi Networks published findings on 19 vulnerabilities in the Pepperl+Fuchs device, urging users to apply mitigations.
Nozomi Networks

More articles in this cluster (2)

Following this threat?

Track Pepperl+Fuchs and CVE-2026-27546 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed