CVE-2023-1698 is a critical vulnerability affecting multiple WAGO products, allowing unauthenticated, remote attackers to create new users and modify device configurations. This flaw carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and potential for full system compromise, denial of service, and unintended behavior. While not listed in CISA's KEV catalog, exploit intelligence indicates the existence of Nuclei templates for remote command execution, suggesting potential for exploitation. Despite its high EPSS and FAUCET Risk Score, there is currently no public Metasploit or ExploitDB code, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20, <= 23CPE matchmatch criteria | cpe:2.3:o:wago:compact_controller_100_firmware:*:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:wago:edge_controller_firmware:22:*:*:*:*:*:*:* | ||
>= 20, <= 23CPE matchmatch criteria | cpe:2.3:o:wago:pfc100_firmware:*:*:*:*:*:*:*:* | ||
>= 20, <= 23CPE matchmatch criteria | cpe:2.3:o:wago:pfc200_firmware:*:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:wago:touch_panel_600_advanced_firmware:22:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.