CVE-2018-12981 is a cross-site scripting (XSS) vulnerability affecting WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. This flaw allows both authenticated and unauthenticated attackers to inject malicious code into the web-based management interface (WBM) via specially crafted requests. The injected code will then be rendered or executed in a user's browser, potentially leading to information disclosure or limited integrity impact. While not actively exploited in the wild (KEV: No), exploit code is publicly available via ExploitDB (EDB-45014), and it has garnered some community discussion and media coverage, including an article from SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 02CPE matchmatch criteria | cpe:2.3:o:wago:762-3000_firmware:*:*:*:*:*:*:*:* | ||
< 02CPE matchmatch criteria | cpe:2.3:o:wago:762-3001_firmware:*:*:*:*:*:*:*:* | ||
< 02CPE matchmatch criteria | cpe:2.3:o:wago:762-3002_firmware:*:*:*:*:*:*:*:* | ||
< 02CPE matchmatch criteria | cpe:2.3:o:wago:762-3003_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.