Wago
wago
114 CVEs • 347 products
Products (347)
Click to collapseToggle
Products (347)
Click to collapse
CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Codesys Wago29750 8202 Firmware 750 8203 Firmware750 8204 Firmware+26 moreJun 17, 2026 May 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. |
1Wago 27750 8202 Firmware 750 8203 Firmware750 8204 Firmware+24 moreJun 17, 2026 May 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges. |
1Wago 27750 8202 Firmware 750 8203 Firmware750 8204 Firmware+24 moreJun 17, 2026 May 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime. |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials. |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management. |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. |
4Emerson Pepperl FuchsWago+1 more7Dtminspector 3 Fdtcontainer ApplicationFdtcontainer Component+4 moreJun 17, 2026 Jan 22, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. |
1Wago 5Pfc 100 Firmware Pfc 200 FirmwareTouch Panel 600 Advanced Firmware+2 moreJun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago...Show more |
1Wago 10750 331 Firmware 750 352 Firmware750 829 Firmware+7 moreJun 17, 2026 Dec 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack. |
1Wago 7750 362 Firmware 750 363 Firmware750 823 Firmware+4 moreJun 17, 2026 Sep 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue...Show more |
1Wago 7750 831 Firmware 750 852 Firmware750 880 Firmware+4 moreJun 17, 2026 Sep 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852, WAGO 750-880/xxx-xxx, WA...Show more |
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote co...Show more |
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. An attacker can send a specially crafted packet to trigger the parsing of this ca...Show more |
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. An attacker can send a specially crafted packet to trigger the parsing of this ca...Show more |
An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A specially crafted XML cache file written to a specific location on the device can cause a heap pointer...Show more |
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a spe...Show more |