VulnSea

Pepperl+Fuchs has 20 CVEs on record. Disclosure cadence is accelerating: 20 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 20. The median CVSS is 8.8 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-78 (14).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
20 prev 0

Products

  • ICE2-8IOL1-G65L-V1D 20
20
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Pepperl+Fuchs vulnerabilities

CVEs affecting Pepperl+Fuchs, newest first. Open any entry for full detail, references, and exploit status.

20 CVEsRSS

CVE-2026-27565Critical· 9.8
5d ago

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

MidnightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.94%via NVD
CVE-2026-27564High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.0%via NVD
CVE-2026-27563High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.0%via NVD
CVE-2026-27562High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.2%via NVD
CVE-2026-27561High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.2%via NVD
CVE-2026-27560High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.2%via NVD
CVE-2026-27559High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27558High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges…

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges…

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27557High· 7.5
5d ago

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.71%via NVD
CVE-2026-27556High· 8.8
5d ago

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.86%via NVD
CVE-2026-27555High· 8.8
5d ago

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.83%via NVD
CVE-2026-27554High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27553Medium· 6.5
5d ago

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

SunlitPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.54%via NVD
CVE-2026-27552High· 8.1
5d ago

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.56%via NVD
CVE-2026-27551High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27550High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27549High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27548High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27547High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27546Critical· 9.8
5d ago

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

MidnightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.95%via NVD
Pepperl+Fuchs vulnerabilities (CVEs) · VulnSea