Where
-Infinity
0

Vendor Risk Score

See how pepperl-fuchs compares to other vendors in security performance

View Risk Score →

Software

pepperl-fuchs wha-gw-f2d2-0-as-z2-eth.eip
8
pepperl-fuchs wha-gw-f2d2-0-as-z2-eth.eip firmware
8
pepperl-fuchs es7528 firmware
5
pepperl-fuchs es8508
5
pepperl-fuchs es8508 firmware
5
pepperl-fuchs es8508f firmware
5
pepperl-fuchs es8510-xt
5
pepperl-fuchs es9528 firmware
5
pepperl-fuchs es9528-xtv2 firmware
5
pepperl-fuchs io-link master 8-pnio-l
5
pepperl-fuchs io-link master dr-8-eip-t
5
pepperl-fuchs io-link master dr-8-pnio
5
pepperl-fuchs io-link master dr-8-pnio-p
5
pepperl-fuchs io-link master 4-eip
4
pepperl-fuchs io-link master 4-eip firmware
4
pepperl-fuchs io-link master 4-pnio
4
pepperl-fuchs io-link master 4-pnio firmware
4
pepperl-fuchs io-link master 8-eip
4
pepperl-fuchs io-link master 8-eip-l
4
pepperl-fuchs io-link master 8-eip-l firmware
4
pepperl-fuchs io-link master 8-pnio
4
pepperl-fuchs io-link master dr-8-eip
4
pepperl-fuchs io-link master dr-8-eip firmware
4
pepperl-fuchs io-link master dr-8-eip-p
4
pepperl-fuchs io-link master dr-8-pnio-t
4
pepperl-fuchs io-link master dr-8-pnio-t firmware
4
pepperl-fuchs eip/modbus firmware
3
pepperl-fuchs ethernet/ip firmware
3
pepperl-fuchs icdm-rx
3
pepperl-fuchs icdm-rx/en1-2st/rj45-din
3
pepperl-fuchs icdm-rx/en1-db9/rj45-pm
3
pepperl-fuchs icdm-rx/en1-st/rj45-din
3
pepperl-fuchs icdm-rx/pn-2st/rj45-din
3
pepperl-fuchs icdm-rx/pn-4db9/2rj45-din
3
pepperl-fuchs icdm-rx/pn-db9/rj45-pm
3
pepperl-fuchs icdm-rx/pn1-2st/rj45-din
3
pepperl-fuchs icdm-rx/pn1-db9/rj45-din
3
pepperl-fuchs icdm-rx/pn1-st/rj45-din
3
pepperl-fuchs icdm-rx/tcp socketserver firmware
3
pepperl-fuchs icdm-rx/tcp-16db9/rj45-rm
3
pepperl-fuchs icdm-rx/tcp-16rj45/rj45-rm
3
pepperl-fuchs icdm-rx/tcp-2db9/rj45-din
3
pepperl-fuchs icdm-rx/tcp-2st/rj45-din
3
pepperl-fuchs icdm-rx/tcp-8db9/2rj45-pm
3
pepperl-fuchs icdm-rx/tcp-db9/rj45-din
3
pepperl-fuchs icdm-rx/tcp-db9/rj45-pm
3
pepperl-fuchs icdm-rx/tcp-db9/rj45-pm2
3
pepperl-fuchs icdm-rx/tcp-st/rj45-din
3
pepperl-fuchs io-link master 8-eip firmware
3
pepperl-fuchs io-link master 8-pnio firmware
3
Severity
9.8
EPSS
0.09%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

Remedy

No update available.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

Remedy

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

Remedy

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

Remedy

For ICRL-M-8RJ45/4SFP-G-DIN and ICRL-M-16RJ45/4CP-G-DIN: Update to Firmware 1.3.1 and deactivate TFTP-Service. For all other devices: An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.
First published (updated )
Severity
9
OS Command Injection, Command Injection
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

Remedy

In order to prevent the exploitation of the reported vulnerabilities, we recommend that the affected units be updated with the following three firmware packages: U-Boot bootloader version 1.36 or newer System image version 1.52 or newer Application base version 1.6.11 or newer
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

Remedy

No update available.
First published (updated )
Severity
8.8
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

Remedy

In order to prevent the exploitation of the reported vulnerabilities, we recommend that the affected units be updated with the following three firmware packages: U-Boot bootloader version 1.36 or newer System image version 1.52 or newer Application base version 1.6.11 or newer
First published (updated )
Severity
8.8
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

Remedy

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.
First published (updated )
Severity
8.6
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.

First published (updated )
Severity
8.6
Code Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

Remedy

M&M Software provides two updated fdtCONTAINER component trees (3.6.20304.x < 3.7 and >= 3.7) see advisory https://cert.vde.com/en-us/advisories/vde-2020-048 for details.
First published (updated )
Severity
7.5
EPSS
0.09%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

First published (updated )
Severity
7.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

Remedy

No update available.
First published (updated )
Severity
7.5
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

Remedy

In order to prevent the exploitation of the reported vulnerabilities, we recommend that the affected units be updated with the following three firmware packages: U-Boot bootloader version 1.36 or newer System image version 1.52 or newer Application base version 1.6.11 or newer
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.

First published (updated )
Severity
7.2
Command Injection
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.

Remedy

An external protective measure is required. 1) Traffic from untrusted networks to the device should be blocked by a firewall. Especially traffic targeting the administration webpage. 2) Administrator and user access should be protected by a secure password and only be available to a very limited group of people.
First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

First published (updated )
Severity
6.6
Null Pointer Dereference
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd

Remedy

In order to prevent the exploitation of the reported vulnerabilities, we recommend that the affected units be updated with the following three firmware packages: U-Boot bootloader version 1.36 or newer System image version 1.52 or newer Application base version 1.6.11 or newer
First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.

First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.

Remedy

No update available.
First published (updated )
Severity
5.6
Infoleak
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited.

Variant CVE-2017-5753 triggers the speculative execution by performing a bounds-check bypass. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the syscall boundary and read privileged memory by conducting targeted cache side-channel attacks.

1 / 4
Source: Red Hat
First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.

Remedy

No update available.
First published (updated )
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

Remedy

No update available.
First published (updated )
Severity
5.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

Remedy

No update available.
First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.

Remedy

No update available.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203