CVEs we hold for Wago
Records whose assigning authority named Wago as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-41732Stack-based buffer overflow via unsafe sscanf in check_cookie()WAGO Indsutrial-Managed-Switches
CVE-2025-41730Stack-based buffer overflow via unsafe sscanf in check_account()WAGO Indsutrial-Managed-Switches
CVE-2025-41713WAGO: Vulnerability in hardware switch circuitWAGO TP600 0762-5206/8000-0001 HW rev. <042500
CVE-2025-41664Improper Permission Handling Enables Unauthorized Access to Firmware and CertificatesWAGO Coupler 0750-0366
CVE-2025-25264Overly Permissive CORS Policy in WAGO Device ManagerWAGO Edge Controller 0752-8303/8000-0002
CVE-2025-1235WAGO: Switches affected by year 2k38 problemWAGO Lean Managed Switches 0852-1816/0010-0000
CVE-2024-41974WAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41973WAGO: Remote Arbitrary File Write with Root Privileges in multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41972WAGO: Arbitrary File Overwrite Leading to Privileged File Read in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41969WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesWAGO CC100 0751/9x01
CVE-2023-4149WAGO: OS Command Injection Vulnerability in Managed SwitchWAGO Industrial Managed Switch (0852-1605)
CVE-2023-4089WAGO: Multiple products vulnerable to local file inclusionWAGO Touch Panel 600 Standard Line
CVE-2023-3379WAGO: Improper Privilege Management in web-based managementWago Edge Controller (752-8303/8000-002)
CVE-2022-45140WAGO: Missing Authentication for Critical FunctionWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-45139WAGO: Origin validation error through CORS misconfigurationWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-45138WAGO: Missing Authentication for Critical FunctionWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-3843WAGO: Exposure of configuration interface in unmanaged switchesWAGO Unmanaged Switch 852-111/000-001
CVE-2022-3738WAGO: Missing authentication for config export functionality in multiple productsWAGO Edge Controller
CVE-2022-3281WAGO: multiple products - Loss of MAC-Address-Filtering after rebootWAGO 752-8303/8000-002 Edge Controller
CVE-2022-22511WAGO PLCs WBM vulnerable to reflected XSSWAGO Series Touch Panel 600 Standard Line (762-4xxx)
CVE-2021-34581WAGO: Denial of Service vulnerability inside the OpenSSL implementationWAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889
CVE-2021-34568WAGO I/O-Check Service prone to Allocation of Resources Without Limits or ThrottlingWAGO 762-6xxx
CVE-2021-21001WAGO: PFC200 Access to files outside the home directoryWAGO Series Ethernet Controller
CVE-2021-21000WAGO: PFC200 Denial of Service due to the number of connections to the runtimeWAGO Series Ethernet Controller
CVE-2021-20993WAGO: Managed Switches: Exposure of sensitive information through directory listingWAGO 0852-1505/000-001
CVE-2020-12522Command Injection Vulnerability in I/O-Check Service of WAGO PFC100, PFC200 and Touch Panel 600 Series with firmware…Wago Touch Panel 600 Marine Line (762-6xxx)
CVE-2020-12506WAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03WAGO 750-890/xxx-xxx
CVE-2020-12505WAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07WAGO 750-889
CVE-2018-25108WAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumptionWAGO 750-889 (Controller KNX IP)
CVE-2018-25090Wago: Improper Neutralization of Input During Web Page Generation in multiple devicesWAGO Fieldbus Coupler Ethernet 3rd Generation
CVE-2015-10123Wago: Buffer Copy without Checking Size of Input in wbm of multiple productsWAGO Fieldbus Coupler Ethernet 3rd Generation
112 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.