Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-27546: Pepperl+Fuchs ICE devices allow admin login without password

CVE-2026-27546 · published 1 day ago
Summary

Several Pepperl+Fuchs ICE controller models can be accessed by anyone on the network, letting them log in as an administrator without providing valid credentials. This could let an attacker change settings, view data, or disrupt operations. Apply the latest firmware updates from the vendor and limit network exposure of these devices.

What to do
  • Update pepperl+fuchs ice2-8iol1-g65l-v1d to version 1.7.4 or later.
  • Update pepperl+fuchs ice2-8iol-g65l-v1d to version 1.7.4 or later.
  • Update pepperl+fuchs ice2-8iol-k45p-rj45 to version 1.7.4 or later.
  • Update pepperl+fuchs ice2-8iol-k45s-rj45 to version 1.7.4 or later.
  • Update pepperl+fuchs ice3-8iol1-g65l-v1d to version 1.7.4 or later.
  • Update pepperl+fuchs ice3-8iol-g65l-v1d to version 1.7.4 or later.
  • Update pepperl+fuchs ice3-8iol-g65l-v1d-y to version 1.7.4 or later.
  • Update pepperl+fuchs ice3-8iol-k45p-rj45 to version 1.7.4 or later.
  • Update pepperl+fuchs ice3-8iol-k45s-rj45 to version 1.7.4 or later.
  • Update phoenix contact iol ma8 pn di8 to version 1.7.4 or later.
  • Update phoenix contact iol ma8 eip di8 to version 1.7.4 or later.
  • Update carlo gavazzi automation yl212cei8m1io to version 1.7.4 or later.
  • Update carlo gavazzi automation yn115cei8rpio to version 1.7.4 or later.
  • Update carlo gavazzi automation yl212cpn8m1io to version 1.7.4 or later.
  • Update carlo gavazzi automation yn115cpn8rpio to version 1.7.4 or later.
Affected software
VendorProductAffected versions
pepperl+fuchs ice2-8iol1-g65l-v1d < 1.7.4
pepperl+fuchs ice2-8iol-g65l-v1d < 1.7.4
pepperl+fuchs ice2-8iol-k45p-rj45 < 1.7.4
pepperl+fuchs ice2-8iol-k45s-rj45 < 1.7.4
pepperl+fuchs ice3-8iol1-g65l-v1d < 1.7.4
pepperl+fuchs ice3-8iol-g65l-v1d < 1.7.4
pepperl+fuchs ice3-8iol-g65l-v1d-y < 1.7.4
pepperl+fuchs ice3-8iol-k45p-rj45 < 1.7.4
pepperl+fuchs ice3-8iol-k45s-rj45 < 1.7.4
phoenix contact iol ma8 pn di8 < 1.7.4
phoenix contact iol ma8 eip di8 < 1.7.4
carlo gavazzi automation yl212cei8m1io < 1.7.4
carlo gavazzi automation yn115cei8rpio < 1.7.4
carlo gavazzi automation yl212cpn8m1io < 1.7.4
carlo gavazzi automation yn115cpn8rpio < 1.7.4
Original advisory text
Authentication Bypass in _account_log
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-288Authentication Bypass Using Alternate Path
Timeline
Published16 Sep 2026
Updated17 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-27546 · MITRE
Track software like this
Free during beta