A critical (CVSS 9.8) command injection flaw lets an unauthenticated remote attacker upload a crafted IODD file to affected IO-Link master devices and execute a shell script as root, with persistence surviving reboot.
What Is It
CVE-2026-27565 is an OS command injection vulnerability (CWE-78) in the IODD file upload handling of multiple rebranded IO-Link master devices. According to the vendor description, "an unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot."
The CVSS v3.1 base score is 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), network-reachable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability. The CVE was assigned by CERT@VDE and published 2026-09-16.
Why It Matters
This is the worst-case shape for an industrial edge device: no authentication, no user interaction, full root, and persistence across reboot. On the vendor's own description of the flaw, an attacker who reaches the device's upload interface would be expected to retain control until the device is patched or reflashed, and IO-Link masters sit directly on the OT plant floor, bridging sensors and actuators to PROFINET and EtherNet/IP networks.
The flaw is not confined to one vendor. The affected product list spans three brands with an identical firmware version range and an identical vulnerability description, which points to a common OEM codebase shipped under multiple labels. If that is the case, asset owners may be exposed through devices they do not associate with the original manufacturer.
What's Vulnerable
All affected products run firmware versions from 1.0.0 up to (but not including) 1.7.4:
- Pepperl+Fuchs: ICE2-8IOL1-G65L-V1D, ICE2-8IOL-G65L-V1D, ICE2-8IOL-K45P-RJ45, ICE2-8IOL-K45S-RJ45, ICE3-8IOL1-G65L-V1D, ICE3-8IOL-G65L-V1D, ICE3-8IOL-G65L-V1D-Y, ICE3-8IOL-K45P-RJ45, ICE3-8IOL-K45S-RJ45
- Phoenix Contact: IOL MA8 PN DI8, IOL MA8 EIP DI8
- Carlo Gavazzi Automation: YL212CEI8M1IO, YN115CEI8RPIO, YL212CPN8M1IO, YN115CPN8RPIO
Patch Status
Per the CERT@VDE advisories and the NVD record, firmware 1.7.4 and later is unaffected; versions below 1.7.4 are affected. Consult the CERT@VDE advisories below for vendor-specific fix and mitigation guidance.
As of this writing, CVE-2026-27565 is not listed in CISA's Known Exploited Vulnerabilities catalog, so no federal remediation deadline applies to it, and neither the NVD record nor the CERT@VDE advisories reference exploitation in the wild. Absence from the KEV catalog is not evidence that exploitation has not occurred; it reflects only that CISA has not published a confirmation. The NVD entry is still in "Received" status, so scoring, references, and affected-product enrichment may change.
Sources
- NVD, CVE-2026-27565: https://nvd.nist.gov/vuln/detail/CVE-2026-27565
- CERT@VDE Advisory VDE-2026-014: https://www.certvde.com/en/advisories/VDE-2026-014/
- CERT@VDE Advisory VDE-2026-027: https://www.certvde.com/en/advisories/VDE-2026-027/
- CERT@VDE Advisory VDE-2026-028: https://www.certvde.com/en/advisories/VDE-2026-028/
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog