Wago
wago
114 CVEs • 347 products
Products (347)
Click to collapseToggle
Products (347)
Click to collapse
CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wago 49750 8100 Firmware 750 8101/025 000 Firmware750 8101 Firmware+46 moreJun 17, 2026 Nov 9, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity an...Show more |
1Wago 78750 8100 Firmware 750 8101/000 010 Firmware750 8101/025 000 Firmware+75 moreJun 17, 2026 Oct 17, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This may allow an remote attacker to circumv...Show more |
1Wago 25750 8100 Firmware 750 8101/025 000 Firmware750 8101 Firmware+22 moreJun 17, 2026 Mar 9, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that c...Show more |
2Codesys Wago30750 8202 Firmware 750 8203 Firmware750 8204 Firmware+27 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition. |
2Codesys Wago30750 8202 Firmware 750 8203 Firmware750 8204 Firmware+27 moreJun 17, 2026 Oct 26, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or loc...Show more |
2Codesys Wago15750 8202 Firmware 750 8203 Firmware750 8204 Firmware+12 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory...Show more |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur...Show more |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. |
1Wago 9750 831/000 002 Firmware 750 831 Firmware750 880/025 000 Firmware+6 moreJun 17, 2026 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cau...Show more |
1Wago 12750 362 Firmware 750 363 Firmware750 823 Firmware+9 moreJun 17, 2026 Aug 31, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware ve...Show more |
2Codesys Wago29750 8202 Firmware 750 8203 Firmware750 8204 Firmware+26 moreJun 17, 2026 May 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. |