WAGO: Multiple vulnerabilities in web-based management of multiple products
Multiple vulnerabilities exist in the Web-Based Management (WBM) interface of WAGO PLCs and controllers. The configuration backend can be accessed without authentication in some cases, allowing root-level write operations. Additionally, CORS misconfiguration enables reflected XSS attacks. Affected products include Compact Controller 100, Edge Controller, PFC100/200, and Touch Panel 600 series (Standard, Advanced, and Marine lines) running firmware versions FW16 through FW23. No patches are currently available for affected firmware versions.
- Network access to HTTP/HTTPS ports (80/443) of the WAGO device
- Device must be reachable from attacker's network location
- No valid credentials required for exploitation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b5f435a9-b9e7-41c5-8108-197ce04f3bb5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.