Wago
wago
114 CVEs • 347 products
Products (347)
Click to collapseToggle
Products (347)
Click to collapse
CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the Tim...Show more |
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into th...Show more |
An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update c...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high perfo...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Mar 11, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt(...Show more |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.3...Show more |
A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data...Show more |
A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recove...Show more |
4Canonical DebianPoint To Point Protocol Project+1 more4Debian Linux Pfc FirmwarePoint To Point Protocol+1 moreJun 17, 2026 Feb 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. |
1Wago 2Pfc100 Firmware Pfc200 FirmwareJun 17, 2026 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware v...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A si...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A spe...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A spe...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmwa...Show more |
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests. |
1Wago 3852 1305 Firmware 852 1505 Firmware852 303 FirmwareJun 17, 2026 Jun 17, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET. |