RESEARCHERS at Nozomi Networks have identified vulnerabilities in shared firmware used by industrial equipment from Pepperl+Fuchs, Phoenix Contact and Carlo Gavazzi Automation. Affected products include Pepperl+Fuchs ICE2 and ICE3 network modules, Phoenix Contact IOL MA8 PN DI8 and IOL MA8 EIP DI8 devices, and Carlo Gavazzi YL212 and YN115 controllers. Firmware versions before 1.7.4 are affected.
The three highlighted flaws are CVE-2026-27565, rated 9.8, which permits remote code execution through a malicious IODD file; CVE-2026-27546, also rated 9.8, an authentication bypass; and CVE-2026-27557, rated 7.5, a path-traversal flaw that can expose private SSH keys. The report says no exploitation has been confirmed in the wild.
According to the vendor advisories, successful attacks could allow unauthorised commands or code with high privileges on the device. The reported attack paths include uploading an IODD file that executes a shell script with root privileges, manipulating login functions to bypass authentication, and sending crafted HTTP requests to vulnerable API endpoints. Other listed defects include command injection and local file inclusion.
The vendors have released firmware version 1.7.8, which the report recommends installing immediately. Where patching is not possible, operators should isolate affected devices, minimise network exposure, ensure they are not accessible from the internet, and limit remote access to secure virtual private networks.