CVE-2026-27565
nicheUnauthenticated command injection in IODD drive firmware (root RCE)
CVE-2026-27565 is an unauthenticated OS command injection flaw (CWE-78) in the affected product's processing of IODD files. A remote attacker can upload a maliciously crafted IODD file with no credentials and no user interaction, causing the device to write and execute a shell script with root privileges. The injected script persists across reboots, giving the attacker a durable foothold at the highest privilege level on the device and a potential pivot point into the attached host or network. Owners and operators of IODD encrypted portable storage devices are affected. No exploitation has been observed, no public proof-of-concept is known, and the issue is not listed in CISA's KEV.
What to do: Monitor the CERT@VDE advisory and IODD vendor channels for a fixed firmware release and update all affected devices as soon as one is available. Until patched, limit which hosts can reach the device's management/file-upload interface, avoid loading IODD files from untrusted sources, and inspect devices for unexpected scripts or persistence mechanisms that survive a reboot, which would indicate compromise.
| IODD encrypted portable drive firmware (file-upload/IODD-file handling interface) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.