Vulnerabilities > Wago > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-21 CVE-2023-4149 OS Command Injection vulnerability in Wago products
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control.
network
low complexity
wago CWE-78
critical
9.8
2023-05-15 CVE-2023-1698 OS Command Injection vulnerability in Wago products
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
network
low complexity
wago CWE-78
critical
9.8
2023-02-27 CVE-2022-45138 Missing Authentication for Critical Function vulnerability in Wago products
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API.
network
low complexity
wago CWE-306
critical
9.8
2023-02-27 CVE-2022-45140 Missing Authentication for Critical Function vulnerability in Wago products
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
network
low complexity
wago CWE-306
critical
9.8
2023-02-16 CVE-2022-3843 Hidden Functionality vulnerability in Wago 852-111/000-001 Firmware 01
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
network
low complexity
wago CWE-912
critical
9.1
2022-11-09 CVE-2021-34566 Classic Buffer Overflow vulnerability in Wago products
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
network
low complexity
wago CWE-120
critical
9.1
2022-11-09 CVE-2021-34569 Out-of-bounds Write vulnerability in Wago products
In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.
network
low complexity
wago CWE-787
critical
9.8
2021-05-13 CVE-2021-20998 Missing Authentication for Critical Function vulnerability in Wago products
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.
network
low complexity
wago CWE-306
critical
9.8
2020-12-17 CVE-2020-12522 OS Command Injection vulnerability in Wago products
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.
network
low complexity
wago CWE-78
critical
9.8
2020-09-30 CVE-2020-12506 Missing Authentication for Critical Function vulnerability in Wago products
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.
network
low complexity
wago CWE-306
critical
9.1