Cyber & AI intelligence
Wasteland.
Briefs indexed2670
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-27565 2026-09-16

CVE-2026-27565: Unauthenticated Root Code Execution in IO-Link Masters via Malicious IODD Upload

"A critical (CVSS 9.8) command injection flaw lets an unauthenticated remote attacker upload a crafted IODD file to affected IO-Link master devices and execute a shell script as root, with persistence surviving reboot."

A critical (CVSS 9.8) command injection flaw lets an unauthenticated remote attacker upload a crafted IODD file to affected IO-Link master devices and execute a shell script as root, with persistence surviving reboot.

What Is It

CVE-2026-27565 is an OS command injection vulnerability (CWE-78) in the IODD file upload handling of multiple rebranded IO-Link master devices. According to the vendor description, "an unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot."

The CVSS v3.1 base score is 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), network-reachable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability. The CVE was assigned by CERT@VDE and published 2026-09-16.

Why It Matters

This is the worst-case shape for an industrial edge device: no authentication, no user interaction, full root, and persistence across reboot. On the vendor's own description of the flaw, an attacker who reaches the device's upload interface would be expected to retain control until the device is patched or reflashed, and IO-Link masters sit directly on the OT plant floor, bridging sensors and actuators to PROFINET and EtherNet/IP networks.

The flaw is not confined to one vendor. The affected product list spans three brands with an identical firmware version range and an identical vulnerability description, which points to a common OEM codebase shipped under multiple labels. If that is the case, asset owners may be exposed through devices they do not associate with the original manufacturer.

What's Vulnerable

All affected products run firmware versions from 1.0.0 up to (but not including) 1.7.4:

Patch Status

Per the CERT@VDE advisories and the NVD record, firmware 1.7.4 and later is unaffected; versions below 1.7.4 are affected. Consult the CERT@VDE advisories below for vendor-specific fix and mitigation guidance.

As of this writing, CVE-2026-27565 is not listed in CISA's Known Exploited Vulnerabilities catalog, so no federal remediation deadline applies to it, and neither the NVD record nor the CERT@VDE advisories reference exploitation in the wild. Absence from the KEV catalog is not evidence that exploitation has not occurred; it reflects only that CISA has not published a confirmation. The NVD entry is still in "Received" status, so scoring, references, and affected-product enrichment may change.

Sources