WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices
Plan PatchCVSS 9.8VDE-2026-031Jul 13, 2026
WAGO
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Certain WAGO System I/O Field devices expose an internal diagnostic capability during early startup that is not documented in public feature sets. This diagnostic mode briefly allows access to system functions before the main operating environment fully initializes, potentially permitting unauthorized interactions with normally protected system components. The issue affects multiple device models in the 0765 series across firmware versions 1.0.0.0 through 1.2.x ranges.
What this means
What could happen
An attacker with network access to a vulnerable WAGO I/O field device could exploit an exposed early-boot diagnostic mode to bypass access controls and gain command execution on the device. This could allow the attacker to alter I/O operations, modify process setpoints, or disable device functionality in critical infrastructure environments.
Who's at risk
WAGO System I/O Field series devices (models 0765-110x, 0765-120x, 0765-150x, 0765-2101, 0765-2102, 0765-410x, 0765-420x, and 0765-450x) used in industrial control, water treatment, power distribution, and manufacturing automation environments where field devices interface with process sensors and actuators.
How it could be exploited
An attacker sends network traffic targeting the device during system startup when the diagnostic mode is active. This unprotected diagnostic interface accepts commands that would normally require authentication. The attacker could execute arbitrary operations on the device's system components before the main operating environment locks down access controls.
Prerequisites
- Network access to the device on the diagnostic interface port during system boot sequence
- Ability to time attack traffic to the initial startup window before operating environment fully initializes
- Knowledge of diagnostic interface command syntax or protocol
remotely exploitableno authentication required during early bootlow complexity attackcritical severityaffects industrial control system field devices
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
I/O System Field 0765-110x/0100-0000≥ 1.0.0.0, < 1.2.1.1001.2.1.100
I/O System Field 0765-120x/0100-0000≥ 1.0.0.0, < 1.2.7.1001.2.7.100
I/O System Field 0765-150x/0100-0000≥ 1.0.0.0, < 1.2.7.1031.2.7.103
I/O System Field 0765-2101/0100-0000≥ 1.0.0.0, < 1.2.1.1021.2.1.102
I/O System Field 0765-2102/0100-0000≥ 1.0.0.0, < 1.2.5.1011.2.5.101
I/O System Field 0765-410x/0100-0000≥ 1.0.0.0, < 1.2.1.1001.2.1.100
I/O System Field 0765-420x/0100-0000≥ 1.0.0.0, < 1.2.7.1001.2.7.100
I/O System Field 0765-450x/0100-0000≥ 1.0.0.0, < 1.2.7.1031.2.7.103
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/8Patching may require device reboot — plan for process interruption
I/O System Field 0765-110x/0100-0000
HOTFIXUpdate I/O System Field 0765-110x/0100-0000 to firmware version 1.2.1.100 or later
I/O System Field 0765-120x/0100-0000
HOTFIXUpdate I/O System Field 0765-120x/0100-0000 to firmware version 1.2.7.100 or later
I/O System Field 0765-150x/0100-0000
HOTFIXUpdate I/O System Field 0765-150x/0100-0000 to firmware version 1.2.7.103 or later
I/O System Field 0765-2101/0100-0000
HOTFIXUpdate I/O System Field 0765-2101/0100-0000 to firmware version 1.2.1.102 or later
I/O System Field 0765-2102/0100-0000
HOTFIXUpdate I/O System Field 0765-2102/0100-0000 to firmware version 1.2.5.101 or later
I/O System Field 0765-410x/0100-0000
HOTFIXUpdate I/O System Field 0765-410x/0100-0000 to firmware version 1.2.1.100 or later
I/O System Field 0765-420x/0100-0000
HOTFIXUpdate I/O System Field 0765-420x/0100-0000 to firmware version 1.2.7.100 or later
I/O System Field 0765-450x/0100-0000
HOTFIXUpdate I/O System Field 0765-450x/0100-0000 to firmware version 1.2.7.103 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b314b151-c9ed-4615-aa06-bff8a6d9d574Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.