CVE-2018-25108 describes an uncontrolled resource consumption vulnerability that allows an unauthenticated remote attacker to cause a Denial of Service (DoS) in the controller. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a severe impact with low attack complexity and no user interaction required. While it has a low EPSS score and no known affected products are listed, its CWE-770 classification highlights a significant resource management flaw. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows no evidence of active exploitation or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WAGO | 750-8100 (Controller PFC100) | >= 0, <= 02.05.23(08)CNA affecteddefault unaffected | |
| WAGO | 750-831 (Controller BACnet/IP) | >= 0, <= 01.02.29(09)CNA affecteddefault unaffected | |
| WAGO | 750-880 (Controller ETH) | >= 0, <= 01.07.03(10)CNA affecteddefault unaffected | |
| WAGO | 750-889 (Controller KNX IP) | >= 0, <= 01.07.13(10)CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.