ZeroHour

CVE-2026-27565

niche

Unauthenticated command injection in IODD drive firmware (root RCE)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-27565 is an unauthenticated OS command injection flaw (CWE-78) in the affected product's processing of IODD files. A remote attacker can upload a maliciously crafted IODD file with no credentials and no user interaction, causing the device to write and execute a shell script with root privileges. The injected script persists across reboots, giving the attacker a durable foothold at the highest privilege level on the device and a potential pivot point into the attached host or network. Owners and operators of IODD encrypted portable storage devices are affected. No exploitation has been observed, no public proof-of-concept is known, and the issue is not listed in CISA's KEV.

What to do: Monitor the CERT@VDE advisory and IODD vendor channels for a fixed firmware release and update all affected devices as soon as one is available. Until patched, limit which hosts can reach the device's management/file-upload interface, avoid loading IODD files from untrusted sources, and inspect devices for unexpected scripts or persistence mechanisms that survive a reboot, which would indicate compromise.

Affected
IODD encrypted portable drive firmware (file-upload/IODD-file handling interface)
Estimated exposure
nichelikely tens of thousands of devices worldwide (order-of-magnitude estimate); most are USB-attached and not directly internet-exposed — IODD is a niche vendor of encrypted portable drive enclosures sold mainly to prosumers and IT professionals, and no public install-base counts or internet-scan statistics are available, so only a rough order-of-magnitude estimate based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.