WAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03
No sign of exploitation. No public exploitation artifact known so far.
WAGO industrial controllers with firmware version 3 or earlier allow attackers to modify device settings without needing a password or login credentials. This is critical because these devices control industrial equipment, and unauthorized changes could disrupt operations or cause safety hazards.
Improper authentication implementation in WAGO 750-series PLCs (versions ≤FW03) enables unauthenticated modification of device configuration via crafted requests. The vulnerability requires network access to the affected device but no credentials, allowing an attacker to alter critical operational settings with direct impact on industrial control system integrity and availability.