CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wago 7Compact Controller 100 Firmware Edge Controller FirmwarePfc100 Firmware+4 moreJun 17, 2026 Nov 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. |
1Wago 7Compact Controller 100 Firmware Edge Controller FirmwarePfc100 Firmware+4 moreJun 17, 2026 Oct 17, 2023 N/A· v4 2.7 LOW· v3 N/A· v2 On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file t...Show more |
1Wago 7Compact Controller 100 Firmware Edge Controller FirmwarePfc100 Firmware+4 moreJun 17, 2026 May 15, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system...Show more |
1Wago 7751 9301 Firmware 752 8303/8000 002 FirmwarePfc100 Firmware+4 moreJun 17, 2026 Feb 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. |
1Wago 7751 9301 Firmware 752 8303/8000 002 FirmwarePfc100 Firmware+4 moreJun 17, 2026 Feb 27, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of dev...Show more |
1Wago 7751 9301 Firmware 752 8303/8000 002 FirmwarePfc100 Firmware+4 moreJun 17, 2026 Feb 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read an...Show more |
1Wago 7751 9301 Firmware 752 8303/8000 002 FirmwarePfc100 Firmware+4 moreJun 17, 2026 Feb 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no i...Show more |
1Wago 7Cc100 Firmware Edge Controller FirmwarePfc100 Firmware+4 moreJun 17, 2026 Jan 19, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to c...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high perfo...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Mar 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt(...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.3...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware v...Show more |
5Abb PhoenixcontactSchneider Electric+2 more106ed1052 1cc01 0ba8 Firmware 6es7211 1ae40 0xb0 Firmware6es7314 6eh04 0ab0 Firmware+7 moreJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network...Show more |