vciy

CVEs we hold for Wago

Records whose assigning authority named Wago as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-4769Unauthenticated Access to Internal Diagnostic InterfaceWAGO 0765-450x/0100-0000
CVE-2026-3587Hidden CLI Function Allows Root AccessWAGO Lean Managed Switch 852-1813/010-001
CVE-2026-2328Backend Access Due to Insufficient Input ValidationWAGO Solution Builder
CVE-2026-22906Hardcoded Key Allows Credential DisclosureWAGO 0852-1328
CVE-2026-22905Authentication Bypass via URI TraversalWAGO 0852-1328
CVE-2026-22904Stack Overflow via Oversized Cookie Fields in lighttpdWAGO 0852-1328
CVE-2026-22903Stack Overflow via SESSIONID Cookie in lighttpdWAGO 0852-1328
CVE-2025-41732Stack-based buffer overflow via unsafe sscanf in check_cookie()WAGO Indsutrial-Managed-Switches
CVE-2025-41730Stack-based buffer overflow via unsafe sscanf in check_account()WAGO Indsutrial-Managed-Switches
CVE-2025-41716Unauthenticated User Enumeration via Missing AuthenticationWAGO Solution Builder
CVE-2025-41715Missing Authentication for Database Access in Web ApplicationWAGO Solution Builder
CVE-2025-41713WAGO: Vulnerability in hardware switch circuitWAGO TP600 0762-5206/8000-0001 HW rev. <042500
CVE-2025-41672WAGO: Vulnerability in WAGO Device SphereWago Device Sphere
CVE-2025-41664Improper Permission Handling Enables Unauthorized Access to Firmware and CertificatesWAGO Coupler 0750-0366
CVE-2025-25265Unauthenticated File Read via Web InterfaceWAGO Edge Controller 0752-8303/8000-0002
CVE-2025-25264Overly Permissive CORS Policy in WAGO Device ManagerWAGO Edge Controller 0752-8303/8000-0002
CVE-2025-1235WAGO: Switches affected by year 2k38 problemWAGO Lean Managed Switches 0852-1816/0010-0000
CVE-2025-0101WAGO: Year 2038 problemWAGO Edge Controller 0752-8303/8000-0002
CVE-2024-41974WAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41973WAGO: Remote Arbitrary File Write with Root Privileges in multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41972WAGO: Arbitrary File Overwrite Leading to Privileged File Read in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41971WAGO: Arbitrary File Overwrite in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41970WAGO: Unauthorized Diagnostic Data Exposure in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41969WAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41968WAGO: Docker Settings Manipulation in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-41967WAGO: Boot Mode Manipulation in Multiple DevicesWAGO CC100 0751/9x01
CVE-2024-1490Wago: Vulnerability in WBM through Open VPNWAGO WP400 (0762-340x)
CVE-2024-12650Wago: Vulnerability in libwagosnmpWAGO TP600 0762-630x/8000-000x
CVE-2023-5872Wago: Vulnerability in Smart Designer Web-ApplicationWago Smart Designer
CVE-2023-5188WAGO Improper Input Validation in IEC61850 Server / TelecontrolWAGO WagoAppRTU
CVE-2023-4149WAGO: OS Command Injection Vulnerability in Managed SwitchWAGO Industrial Managed Switch (0852-1605)
CVE-2023-4089WAGO: Multiple products vulnerable to local file inclusionWAGO Touch Panel 600 Standard Line
CVE-2023-3379WAGO: Improper Privilege Management in web-based managementWago Edge Controller (752-8303/8000-002)
CVE-2023-1698WAGO: WBM Command Injection in multiple productsWAGO Touch Panel 600 Standard Line
CVE-2023-1620WAGO: DoS in multiple products in multiple versions using CodesysWago 750-889
CVE-2023-1619WAGO: DoS in multiple versions of multiple productsWago 750-889
CVE-2023-1150WAGO: Series 750-3x/-8x prone to MODBUS server DoSWAGO 750-893
CVE-2022-50926WAGO 750-8212 PFC200 G2 2ETH RS Privilege EscalationWAGO 750-8212 PFC200
CVE-2022-45140WAGO: Missing Authentication for Critical FunctionWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-45139WAGO: Origin validation error through CORS misconfigurationWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-45138WAGO: Missing Authentication for Critical FunctionWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-45137WAGO: Reflective Cross-Site ScriptingWAGO Touch Panel 600 Standard Line (762-4xxx)
CVE-2022-3843WAGO: Exposure of configuration interface in unmanaged switchesWAGO Unmanaged Switch 852-111/000-001
CVE-2022-3738WAGO: Missing authentication for config export functionality in multiple productsWAGO Edge Controller
CVE-2022-3281WAGO: multiple products - Loss of MAC-Address-Filtering after rebootWAGO 752-8303/8000-002 Edge Controller
CVE-2022-22511WAGO PLCs WBM vulnerable to reflected XSSWAGO Series Touch Panel 600 Standard Line (762-4xxx)
CVE-2021-34581WAGO: Denial of Service vulnerability inside the OpenSSL implementationWAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889
CVE-2021-34578WAGO: Authentication Vulnerability in Web-Based ManagementWAGO PLC
CVE-2021-34569WAGO I/O-Check Service prone to Out-of-bounds WriteWAGO 762-6xxx
CVE-2021-34568WAGO I/O-Check Service prone to Allocation of Resources Without Limits or ThrottlingWAGO 762-6xxx
CVE-2021-34567WAGO I/O-Check Service prone to Out-of-bounds ReadWAGO 762-6xxx
CVE-2021-34566WAGO I/O-Check Service prone to Memory OverflowWAGO 762-6xxx
CVE-2021-21001WAGO: PFC200 Access to files outside the home directoryWAGO Series Ethernet Controller
CVE-2021-21000WAGO: PFC200 Denial of Service due to the number of connections to the runtimeWAGO Series Ethernet Controller
CVE-2021-20998WAGO: Managed Switches: Unauthorized creation of user accountsWAGO 0852-1505/000-001
CVE-2021-20997WAGO: Managed Switches: Unauthorized access to password hashesWAGO 0852-1505/000-001
CVE-2021-20996WAGO: Managed Switches: Unsecure Cookie settingsWAGO 0852-1505/000-001
CVE-2021-20995WAGO: Managed Switches: Storage of user credentials in a cookieWAGO 0852-1505/000-001
CVE-2021-20994WAGO: Managed Switches: Reflected Cross-site ScriptingWAGO 0852-1505/000-001
CVE-2021-20993WAGO: Managed Switches: Exposure of sensitive information through directory listingWAGO 0852-1505/000-001
CVE-2020-6090no title heldn/a Wago
CVE-2020-12522Command Injection Vulnerability in I/O-Check Service of WAGO PFC100, PFC200 and Touch Panel 600 Series with firmware…Wago Touch Panel 600 Marine Line (762-6xxx)
CVE-2020-12516WAGO: PLC families 750-88x and 750-352 prone to DoS attackWAGO 750-889
CVE-2020-12506WAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03WAGO 750-890/xxx-xxx
CVE-2020-12505WAGO: Vulnerability in web-based authentication in WAGO 750-8XX Version <= FW07WAGO 750-889
CVE-2019-5186no title heldn/a Wago
CVE-2019-5185no title heldn/a Wago
CVE-2019-5184no title heldn/a Wago
CVE-2019-5182no title heldWAGO PFC200
CVE-2019-5181no title heldWAGO PFC200
CVE-2019-5180no title heldWAGO PFC200
CVE-2019-5179no title heldWAGO PFC200
CVE-2019-5178no title heldWAGO PFC200
CVE-2019-5177no title heldWAGO PFC200
CVE-2019-5176no title heldWAGO PFC200
CVE-2019-5175no title heldWAGO PFC200
CVE-2019-5174no title heldWAGO PFC200 Firmware
CVE-2019-5173no title heldWAGO PFC200
CVE-2019-5172no title heldWAGO PFC200
CVE-2019-5171no title heldWAGO PFC200
CVE-2019-5170no title heldWAGO PFC200
CVE-2019-5169no title heldWAGO PFC200
CVE-2019-5168no title heldWAGO PFC200 Firmware
CVE-2019-5167no title heldWAGO PFC200 Firmware
CVE-2019-5166no title heldWAGO PFC200 Firmware
CVE-2019-5161no title heldWAGO PFC200 Firmware
CVE-2019-5160no title heldWAGO PFC200 Firmware
CVE-2019-5159no title heldWAGO e!COCKPIT
CVE-2019-5158no title heldWAGO e!COCKPIT
CVE-2019-5157no title heldWAGO PFC200 Firmware
CVE-2019-5156no title heldWAGO PFC200 Firmware
CVE-2019-5155no title heldWAGO PFC200 Firmware
CVE-2019-5149no title heldWAGO PFC100 Firmware
CVE-2019-5135no title heldWAGO PFC100 Firmware
CVE-2019-5134no title heldWAGO PFC100 Firmware
CVE-2019-5107no title heldWAGO e!Cockpit
CVE-2019-5106no title heldWAGO e!Cockpit
CVE-2019-5082no title heldn/a WAGO PFC100
CVE-2019-5081no title heldn/a WAGO PFC100
CVE-2019-5080no title heldn/a WAGO PFC100
CVE-2019-5079no title heldn/a WAGO PFC100
CVE-2019-5078no title heldn/a WAGO PFC100
CVE-2019-5077no title heldn/a WAGO PFC100
CVE-2019-5075no title heldn/a WAGO PFC100
CVE-2019-5074no title heldn/a WAGO PFC100
CVE-2019-5073no title heldn/a WAGO PFC100
CVE-2018-8836no title heldWAGO 750 Series
CVE-2018-5459no title heldn/a WAGO PFC200 Series
CVE-2018-25108WAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumptionWAGO 750-889 (Controller KNX IP)
CVE-2018-25090Wago: Improper Neutralization of Input During Web Page Generation in multiple devicesWAGO Fieldbus Coupler Ethernet 3rd Generation
CVE-2016-9362no title heldn/a WAGO Ethernet cards
CVE-2015-10123Wago: Buffer Copy without Checking Size of Input in wbm of multiple productsWAGO Fieldbus Coupler Ethernet 3rd Generation

112 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.