AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Wago
WA
Platform

Wago

750 Series modular fieldbus I/O, PFC200 controllers, WAGO-I/O-PRO and e!COCKPIT engineering software.

https://www.wago.com →
83
Total CVEs
0
Resources
26
CRIT
39
HIGH
17
MED
1
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
26 / 83
CVE-2021-20998CRITICAL

In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

May 13, 2021
10.0
CVE-2020-12522CRITICAL

The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.

Dec 17, 2020
10.0
CVE-2022-50926CRITICAL

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.

Jan 13, 2026
9.8
CVE-2023-1698CRITICAL

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

May 15, 2023
9.8
CVE-2021-34569CRITICAL

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

Nov 9, 2022
9.8
CVE-2021-34578CRITICAL

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

Aug 31, 2021
9.8
CVE-2019-5082CRITICAL

An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

Jan 8, 2020
9.8
CVE-2019-5079CRITICAL

An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
9.8
CVE-2019-5075CRITICAL

An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
9.8
CVE-2019-5081CRITICAL

An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
9.8
CVE-2019-5074CRITICAL

An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
9.8
CVE-2019-12550CRITICAL

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

Jun 17, 2019
9.8
CVE-2019-12549CRITICAL

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.

Jun 17, 2019
9.8
CVE-2019-10712CRITICAL

The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

May 7, 2019
9.8
CVE-2015-6473CRITICAL

WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.

Aug 22, 2017
9.8
CVE-2015-6472CRITICAL

WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.

Aug 22, 2017
9.8
CVE-2022-3843CRITICAL

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

Feb 16, 2023
9.1
CVE-2021-34566CRITICAL

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

Nov 9, 2022
9.1
CVE-2021-21001CRITICAL

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

May 24, 2021
9.1
CVE-2020-12506CRITICAL

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.

Sep 30, 2020
9.1
CVE-2019-5161CRITICAL

An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.

Mar 11, 2020
9.1
CVE-2019-5160CRITICAL

An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker controlled Azure IoT Hub node.

Mar 11, 2020
9.1
CVE-2019-5080CRITICAL

An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A single packet can cause a denial of service and weaken credentials resulting in the default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.

Dec 18, 2019
9.1
CVE-2019-5078CRITICAL

An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
9.1
CVE-2019-5077CRITICAL

An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.

Dec 18, 2019
9.1
CVE-2016-9362CRITICAL

An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 prior to FW09 (released August 2016), and WAGO 0758-0874-0000-0111. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to edit and to view settings without authenticating.

Feb 13, 2017
9.1
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2021-20998CRITICAL
10.0
In multiple managed switches by WAGO in different versions without authorization and with specially …May 13, 2021›
CVE-2020-12522CRITICAL
10.0
The reported vulnerability allows an attacker who has network access to the device to execute code w…Dec 17, 2020›
CVE-2022-50926CRITICAL
9.8
WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows a…Jan 13, 2026›
CVE-2023-1698CRITICAL
9.8
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create ne…May 15, 2023›
CVE-2021-34569CRITICAL
9.8
In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet conta…Nov 9, 2022›
CVE-2021-34578CRITICAL
9.8
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameter…Aug 31, 2021›
CVE-2019-5082CRITICAL
9.8
An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functiona…Jan 8, 2020›
CVE-2019-5079CRITICAL
9.8
An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functio…Dec 18, 2019›
CVE-2019-5075CRITICAL
9.8
An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdeta…Dec 18, 2019›
CVE-2019-5081CRITICAL
9.8
An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functi…Dec 18, 2019›
CVE-2019-5074CRITICAL
9.8
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' func…Dec 18, 2019›
CVE-2019-12550CRITICAL
9.8
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded u…Jun 17, 2019›
CVE-2019-12549CRITICAL
9.8
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded p…Jun 17, 2019›
CVE-2019-10712CRITICAL
9.8
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 7…May 7, 2019›
CVE-2015-6473CRITICAL
9.8
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.Aug 22, 2017›
CVE-2015-6472CRITICAL
9.8
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential man…Aug 22, 2017›
CVE-2022-3843CRITICAL
9.1
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration inte…Feb 16, 2023›
CVE-2021-34566CRITICAL
9.1
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special…Nov 9, 2022›
CVE-2021-21001CRITICAL
9.1
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised att…May 24, 2021›
CVE-2020-12506CRITICAL
9.1
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attac…Sep 30, 2020›
CVE-2019-5161CRITICAL
9.1
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of…Mar 11, 2020›
CVE-2019-5160CRITICAL
9.1
An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality…Mar 11, 2020›
CVE-2019-5080CRITICAL
9.1
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functional…Dec 18, 2019›
CVE-2019-5078CRITICAL
9.1
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functional…Dec 18, 2019›
CVE-2019-5077CRITICAL
9.1
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functiona…Dec 18, 2019›
CVE-2016-9362CRITICAL
9.1
An issue was discovered in WAGO 750-8202/PFC200 prior to FW04 (released August 2015), WAGO 750-881 p…Feb 13, 2017›