← Back

Wago

wago

114 CVEs • 347 products

Products (347)

Click to collapse
Toggle
E!cockpit
e!cockpit

CVEs (114)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wago
20852 1322 Firmware
0852 1328 Firmware
Jun 17, 2026
Dec 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
1Wago
20852 1322 Firmware
0852 1328 Firmware
Jun 17, 2026
Dec 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
1Wago
2Telecontrol Configurator
Wagoapprtu
Jun 17, 2026
Dec 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packet...Show more
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.Show less
1Wago
30852 0602 Firmware
0852 0603 Firmware0852 1605 Firmware
Jun 17, 2026
Nov 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability...Show more
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based management.Show less
1Wago
7Compact Controller 100 Firmware
Edge Controller FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Nov 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
1Wago
7Compact Controller 100 Firmware
Edge Controller FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Oct 17, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file t...Show more
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.Show less
1Wago
76750 331 Firmware
750 8202/000 011 Firmware750 8202/000 012 Firmware+73 more
Jun 17, 2026
Jun 26, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
1Wago
76750 331 Firmware
750 8202/000 011 Firmware750 8202/000 012 Firmware+73 more
Jun 17, 2026
Jun 26, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
1Wago
18750 362/000 001 Firmware
750 362/040 000 Firmware750 362 Firmware+15 more
Jun 17, 2026
Jun 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
1Wago
7Compact Controller 100 Firmware
Edge Controller FirmwarePfc100 Firmware+4 more
Jun 17, 2026
May 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system...Show more
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.Show less
1Wago
7751 9301 Firmware
752 8303/8000 002 FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
1Wago
7751 9301 Firmware
752 8303/8000 002 FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of dev...Show more
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.Show less
1Wago
7751 9301 Firmware
752 8303/8000 002 FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read an...Show more
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.Show less
1Wago
7751 9301 Firmware
752 8303/8000 002 FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no i...Show more
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.Show less
1Wago
1852 111/000 001 Firmware
Jun 17, 2026
Feb 16, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of paramete...Show more
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters. Show less
1Wago
7Cc100 Firmware
Edge Controller FirmwarePfc100 Firmware+4 more
Jun 17, 2026
Jan 19, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to c...Show more
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull. Show less
4Codesys
FestoPilz+1 more
64750 8100 Firmware
750 8101 Firmware750 8102 Firmware+61 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local a...Show more
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.Show less
1Wago
49750 8100 Firmware
750 8101/025 000 Firmware750 8101 Firmware+46 more
Jun 17, 2026
Nov 9, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.
1Wago
49750 8100 Firmware
750 8101/025 000 Firmware750 8101 Firmware+46 more
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.
1Wago
49750 8100 Firmware
750 8101/025 000 Firmware750 8101 Firmware+46 more
Jun 17, 2026
Nov 9, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.