<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_wagogmbhcokg/10</id>
  <title>Most recent entries from csaf_wagogmbhcokg</title>
  <updated>2026-10-02T07:11:03.357880+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-102</id>
    <title>VDE-2025-102 — WAGO: Multiple Devices are affected by a Vulnerability in BACnet IP Stack</title>
    <updated>2026-10-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intended directory, so relative paths can be used to reach files elsewhere in the file system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-102"/>
    <published>2026-10-01T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-081</id>
    <title>VDE-2025-081 — WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE</title>
    <updated>2026-10-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are &lt;4.10.0 (FW32) and &lt;4.10.0 (70).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-081"/>
    <published>2026-10-01T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-007</id>
    <title>VDE-2025-007 — WAGO: Year 2038 problem</title>
    <updated>2026-08-07T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Year 2038 Problem affects systems using a 32-bit integer to represent time as the number of seconds since January 1, 1970. On January 19, 2038, at 03:14:07 UTC, the time value will exceed the maximum for a 32-bit integer, causing an overflow and resetting it to a negative number.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-007"/>
    <published>2025-04-15T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-031</id>
    <title>VDE-2026-031 — WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices</title>
    <updated>2026-07-13T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-031"/>
    <published>2026-07-13T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-008</id>
    <title>VDE-2024-008 — Wago: Vulnerability in WBM through Open VPN</title>
    <updated>2026-04-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-008"/>
    <published>2026-04-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-021</id>
    <title>VDE-2026-021 — WAGO: Multiple Vulnerabilities in WAGO VC Hub</title>
    <updated>2026-03-30T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-021"/>
    <published>2026-03-30T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-010</id>
    <title>VDE-2026-010 — WAGO: Multiple Vulnerabilities in WAGO Solution Builder and WAGO Device Sphere</title>
    <updated>2026-03-30T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-010"/>
    <published>2026-03-30T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-020</id>
    <title>VDE-2026-020 — WAGO: Vulnerability in managed switches</title>
    <updated>2026-03-23T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been found affecting the Managed Switches of WAGO. An unauthenticated attacker can fully compromise the device via an undocumented function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-020"/>
    <published>2026-03-23T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-004</id>
    <title>VDE-2026-004 — WAGO: Vulnerabilities in Managed Switch</title>
    <updated>2026-02-09T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been identified in the WAGO 852‑1328 device's web‑based management interface, which is implemented using a modified lighttpd server and custom CGI binaries. These issues include multiple stack buffer overflows, an authentication bypass, and insecure credential storage.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-004"/>
    <published>2026-02-09T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-095</id>
    <title>VDE-2025-095 — WAGO: Vulnerabilities in WAGO Industrial-Managed Switches</title>
    <updated>2026-01-19T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Two remote stack buffer overflow vulnerabilities were discovered in WAGO industrial switches. These issues originate from unsafe input handling in custom HTTP request parsing functions within the lighttpd binary. The affected binary lacks modern security features such as PIE and RELRO, increasing the risk of successful exploitation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-095"/>
    <published>2025-12-10T10:00:00+00:00</published>
  </entry>
</feed>
