CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “pepperl-fuchs”

27 vulnerabilities found for “pepperl-fuchs”

Page 1 of 2

CVE-2024-5849
HIGH7.1

An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.

pepperl-fuchs / icdm-rx\/tcp_socketserver_firmware+7
Network
Published Aug 13, 2024
Page 1 of 2
CVE-2024-38502
HIGH7.1

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

pepperl-fuchs / icdm-rx\/tcp_socketserver_firmware+7
Network
Published Aug 13, 2024
CVE-2024-38501
MEDIUM6.1

An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.

pepperl-fuchs / icdm-rx\/tcp_socketserver_firmware+7
Network
Published Aug 13, 2024
CVE-2024-6421
HIGH7.5

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

pepperl-fuchs / oit700-f113-b12-cb_firmware+3
Network
Published Jul 10, 2024
CVE-2024-6422
CRITICAL9.8

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

pepperl-fuchs / oit700-f113-b12-cb_firmware+3
Network
Published Jul 10, 2024
CVE-2021-34559
MEDIUM5.4

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Network
Published Aug 31, 2021
CVE-2021-34560
MEDIUM5.5

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

pepperl-fuchs / wha-gw-f2d2-0-as-z2-eth_firmware+1
Local
Published Aug 31, 2021
CVE-2021-20988
HIGH8.6

In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.

hilscher / rcx_rtos+8
Network
Published May 13, 2021
CVE-2021-20987
HIGH8.6

A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

hilscher / ethernet\/ip_adapter_firmware+7
Network
Published Feb 16, 2021
CVE-2021-20986
HIGH7.5

A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.

hilscher / profinet_io_device_firmware+23
Network
Published Feb 16, 2021
CVE-2020-12514
MEDIUM6.6

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd

pepperl-fuchs / io-link_master_4-eip_firmware+11
Network
Published Jan 22, 2021
CVE-2020-12512
HIGH7.5

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

pepperl-fuchs / io-link_master_4-eip_firmware+11
Network
Published Jan 22, 2021
CVE-2020-12513
HIGH7.5

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

pepperl-fuchs / io-link_master_4-eip_firmware+11
Network
Published Jan 22, 2021
CVE-2020-12525
HIGH7.3

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

emerson / rosemount_transmitter_interface_software+10
Local
Published Jan 22, 2021
CVE-2020-12511
HIGH8.8

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

pepperl-fuchs / io-link_master_4-eip_firmware+11
Network
Published Jan 22, 2021
CVE-2020-12503
HIGH7.2

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.

pepperl-fuchs / es7510-xt_firmware+29
Network
Published Oct 15, 2020
CVE-2020-12504
CRITICAL9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

pepperl-fuchs / es7510-xt_firmware+28
Network
Published Oct 15, 2020
CVE-2020-12502
HIGH8.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

pepperl-fuchs / es7510-xt_firmware+24
Network
Published Oct 15, 2020
CVE-2020-12501
CRITICAL9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

pepperl-fuchs / es7510-xt_firmware+25
Network
Published Oct 15, 2020
CVE-2020-12500
CRITICAL9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

pepperl-fuchs / es7510-xt_firmware+12
Network
Published Oct 15, 2020