WAGO: Improper privilege management in web-based management
A misconfiguration of access rights in the web-based management interface allows an authenticated user with low privileges to reset passwords of other users (except root). This privilege escalation flaw affects WAGO Compact Controller 100, Edge Controller, PFC100, PFC200, and Touch Panel 600 series devices. An attacker with a valid low-privilege account can use the configuration tool to reset administrator credentials and gain full control of the device, allowing modification of controller configuration, setpoints, and process logic.
- Valid low-privilege user credentials for the web-based management interface
- Network access to the web management port (typically 80/443)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/37eaafbe-5dda-470f-b2ea-e321216a1edbGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.