<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:17:07 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-45140 — WAGO: Missing Authentication for Critical Function</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-45140</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; WAGO Compact Controller CC100 (751-9301), WAGO Edge Controller (752-8303/8000-002), WAGO PFC100 (750-81xx/xxx-xxx), WAGO PFC200 (750-82xx/xxx-xxx), WAGO Touch Panel 600 Advanced Line (762-5xxx), WAGO Touch Panel 600 Marine Line (762-6xxx), WAGO Touch Panel 600 Standard Line (762-4xxx)&lt;/p&gt;
&lt;p&gt;The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; WAGO Compact Controller CC100 (751-9301), WAGO Edge Controller (752-8303/8000-002), WAGO PFC100 (750-81xx/xxx-xxx), WAGO PFC200 (750-82xx/xxx-xxx), WAGO Touch Panel 600 Advanced Line (762-5xxx), WAGO Touch Panel 600 Marine Line (762-6xxx), WAGO Touch Panel 600 Standard Line (762-4xxx)&lt;/p&gt;
&lt;p&gt;The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-45140</guid>
    </item>
    <item>
      <title>VDE-2022-060 — WAGO: Multiple vulnerabilities in web-based management of multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-060</link>
      <description>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
The configuration backend can in some cases be used without authentication and to write data with root privileges. Additionally, the web-based management suffers a CORS misconfiguration and allows reflected XSS (Cross-Site Scripting) attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
The configuration backend can in some cases be used without authentication and to write data with root privileges. Additionally, the web-based management suffers a CORS misconfiguration and allows reflected XSS (Cross-Site Scripting) attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-060</guid>
    </item>
  </channel>
</rss>
