Wago manufactures industrial automation controllers and programmable logic devices—particularly its PFC200 series and modular I/O terminals—that serve critical infrastructure and manufacturing environments, placing it among the most prominent vendors in the operational-technology landscape. Vulnerabilities affecting the vendor skew strongly toward critical severity, reflecting the memory-safety and authentication challenges inherent to embedded control systems, and the exposure recurs across product lines through weakness classes including out-of-bounds writes, OS command injection, missing authentication for critical functions, and cross-site scripting. The concentration of high-severity flaws across Wago's controller firmware and networked devices creates elevated risk for defenders managing industrial networks, since many instances remain in long-service deployments with constrained patching windows. Defenders should prioritize inventory and network segmentation of affected Wago devices and align remediation with maintenance schedules; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wago over time
Signals from CVEs in this vendor scope (114 CVEs).
114 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1698CRITICAL In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behav | May 15, 2023 | 9.8 | 83 | NO | YES |
CVE-2018-12980HIGH An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to | Jul 12, 2018 | 8.8 | 53 | NO | YES |
CVE-2020-8597CRITICAL eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | Feb 3, 2020 | 9.8 | 41 | NO | NO |
CVE-2018-12979MEDIUM An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by | Jul 12, 2018 | 6.5 | 34 | NO | YES |
CVE-2019-12549CRITICAL WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the cor | Jun 17, 2019 | 9.8 | 33 | NO | NO |
CVE-2021-30188CRITICAL CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. | May 25, 2021 | 9.8 | 32 | NO | NO |
CVE-2019-12550CRITICAL WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET. | Jun 17, 2019 | 9.8 | 32 | NO | NO |
CVE-2025-41732CRITICAL An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device | Dec 10, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-41730CRITICAL An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full devic | Dec 10, 2025 | 9.8 | 31 | NO | NO |
CVE-2021-34569CRITICAL In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory. | Nov 9, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (114 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wago.
Media articles that mention a CVE ID that affects a product developed by Wago — matched by CVE ID, not by vendor name.