Vulnerabilidades em Wago
98 resultadosAnálise Vexday
Wago apresenta 34 vulnerabilidades catalogadas, nenhuma em exploração ativa conhecida (KEV) e sem críticas nos últimos 90 dias, indicando risco controlado no curto prazo. A fraqueza dominante é CWE-1288 (improper validation of inconsistent expression in code), sugerindo problemas sistêmicos em validação de lógica que demandam revisão arquitetural. O portfólio não mostra movimento recente de descobertas, o que reduz urgência mas não elimina a necessidade de remediação estrutural.
CVE-2024-41971HIGHWAGO: Arbitrary File Overwrite in Multiple DevicesEPSS 0.6%CVE-2024-41973HIGHWAGO: Remote Arbitrary File Write with Root Privileges in multiple DevicesEPSS 0.6%CVE-2024-41972MEDIUMWAGO: Arbitrary File Overwrite Leading to Privileged File Read in Multiple DevicesEPSS 0.6%CVE-2022-22511MEDIUMWAGO PLCs WBM vulnerable to reflected XSSEPSS 0.6%CVE-2021-20995MEDIUMWAGO: Managed Switches: Storage of user credentials in a cookieEPSS 0.5%CVE-2026-22904CRITICALStack Overflow via Oversized Cookie Fields in lighttpdEPSS 0.5%CVE-2019-5176—An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.5%CVE-2019-5182—An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.5%CVE-2018-25108HIGHWAGO: Denial of service in 750-8xx controller due to uncontrolled resource consumptionEPSS 0.5%CVE-2024-41969HIGHWAGO: CODESYS V3 Configuration Authentication Bypass in Multiple DevicesEPSS 0.5%CVE-2022-50926HIGHWAGO 750-8212 PFC200 G2 2ETH RS Privilege EscalationEPSS 0.5%CVE-2023-4089LOWWAGO: Multiple products vulnerable to local file inclusionEPSS 0.5%CVE-2025-41715CRITICALMissing Authentication for Database Access in Web ApplicationEPSS 0.5%CVE-2019-5177—An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 FiEPSS 0.5%CVE-2026-4769CRITICALUnauthenticated Access to Internal Diagnostic InterfaceEPSS 0.4%CVE-2025-41730CRITICALStack-based buffer overflow via unsafe sscanf in check_account()EPSS 0.4%CVE-2025-41732CRITICALStack-based buffer overflow via unsafe sscanf in check_cookie()EPSS 0.4%CVE-2025-25265MEDIUMUnauthenticated File Read via Web InterfaceEPSS 0.4%CVE-2018-25090MEDIUMWago: Improper Neutralization of Input During Web Page Generation in multiple devicesEPSS 0.4%CVE-2024-41967HIGHWAGO: Boot Mode Manipulation in Multiple DevicesEPSS 0.4%