CVE-2026-27565
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.94%
- CWE
- CWE-78
- Published
- 2026-09-16
- Last modified
- 2026-09-16
Affected products
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45
Weakness type
Related vulnerabilities
- CVE-2026-83549 — Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
- CVE-2026-86152 — Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection
- CVE-2026-82004 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
- CVE-2026-79724 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81467 — Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS C
- CVE-2026-71376 — OS Command Injection Vulnerability in Cosminexus Component Container
- CVE-2026-57124 — PraisonAI UI MCP connect endpoint allows unauthenticated local command execution
- CVE-2026-53611 — Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation