<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_wagogmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:11:04 +0000</lastBuildDate>
    <item>
      <title>VDE-2025-102 — WAGO: Multiple Devices are affected by a Vulnerability in BACnet IP Stack</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-102</link>
      <description>&lt;p&gt;Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intended directory, so relative paths can be used to reach files elsewhere in the file system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple WAGO devices are affected by a vulnerability in the dynamic creation of BACnet File Objects. The object name is used as a file path without sufficient validation and is not restricted to the intended directory, so relative paths can be used to reach files elsewhere in the file system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-102</guid>
      <pubDate>Thu, 01 Oct 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-081 — WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-081</link>
      <description>&lt;p&gt;Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are &amp;lt;4.10.0 (FW32) and &amp;lt;4.10.0 (70).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are &amp;lt;4.10.0 (FW32) and &amp;lt;4.10.0 (70).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-081</guid>
      <pubDate>Thu, 01 Oct 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-007 — WAGO: Year 2038 problem</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-007</link>
      <description>&lt;p&gt;The Year 2038 Problem affects systems using a 32-bit integer to represent time as the number of seconds since January 1, 1970. On January 19, 2038, at 03:14:07 UTC, the time value will exceed the maximum for a 32-bit integer, causing an overflow and resetting it to a negative number.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Year 2038 Problem affects systems using a 32-bit integer to represent time as the number of seconds since January 1, 1970. On January 19, 2038, at 03:14:07 UTC, the time value will exceed the maximum for a 32-bit integer, causing an overflow and resetting it to a negative number.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-007</guid>
      <pubDate>Tue, 15 Apr 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-031 — WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-031</link>
      <description>&lt;p&gt;Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-031</guid>
      <pubDate>Mon, 13 Jul 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-008 — Wago: Vulnerability in WBM through Open VPN</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-008</link>
      <description>&lt;p&gt;An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-008</guid>
      <pubDate>Wed, 08 Apr 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-021 — WAGO: Multiple Vulnerabilities in WAGO VC Hub</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-021</link>
      <description>&lt;p&gt;The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design Project Permission can upload images.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-021</guid>
      <pubDate>Mon, 30 Mar 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-010 — WAGO: Multiple Vulnerabilities in WAGO Solution Builder and WAGO Device Sphere</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-010</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-010</guid>
      <pubDate>Mon, 30 Mar 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-020 — WAGO: Vulnerability in managed switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-020</link>
      <description>&lt;p&gt;A vulnerability has been found affecting the Managed Switches of WAGO. An unauthenticated attacker can fully compromise the device via an undocumented function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been found affecting the Managed Switches of WAGO. An unauthenticated attacker can fully compromise the device via an undocumented function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-020</guid>
      <pubDate>Mon, 23 Mar 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-004 — WAGO: Vulnerabilities in Managed Switch</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-004</link>
      <description>&lt;p&gt;Several vulnerabilities have been identified in the WAGO 852‑1328 device&amp;#39;s web‑based management interface, which is implemented using a modified lighttpd server and custom CGI binaries. These issues include multiple stack buffer overflows, an authentication bypass, and insecure credential storage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been identified in the WAGO 852‑1328 device&amp;#39;s web‑based management interface, which is implemented using a modified lighttpd server and custom CGI binaries. These issues include multiple stack buffer overflows, an authentication bypass, and insecure credential storage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-004</guid>
      <pubDate>Mon, 09 Feb 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-095 — WAGO: Vulnerabilities in WAGO Industrial-Managed Switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-095</link>
      <description>&lt;p&gt;Two remote stack buffer overflow vulnerabilities were discovered in WAGO industrial switches. These issues originate from unsafe input handling in custom HTTP request parsing functions within the lighttpd binary. The affected binary lacks modern security features such as PIE and RELRO, increasing the risk of successful exploitation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Two remote stack buffer overflow vulnerabilities were discovered in WAGO industrial switches. These issues originate from unsafe input handling in custom HTTP request parsing functions within the lighttpd binary. The affected binary lacks modern security features such as PIE and RELRO, increasing the risk of successful exploitation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-095</guid>
      <pubDate>Wed, 10 Dec 2025 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
