Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wago

First CVE: Sep 7, 2012Active for: 14 yearsTotal CVEs: 114
42.5
VTI Score
High

Wago manufactures industrial automation controllers and programmable logic devices—particularly its PFC200 series and modular I/O terminals—that serve critical infrastructure and manufacturing environments, placing it among the most prominent vendors in the operational-technology landscape. Vulnerabilities affecting the vendor skew strongly toward critical severity, reflecting the memory-safety and authentication challenges inherent to embedded control systems, and the exposure recurs across product lines through weakness classes including out-of-bounds writes, OS command injection, missing authentication for critical functions, and cross-site scripting. The concentration of high-severity flaws across Wago's controller firmware and networked devices creates elevated risk for defenders managing industrial networks, since many instances remain in long-service deployments with constrained patching windows. Defenders should prioritize inventory and network segmentation of affected Wago devices and align remediation with maintenance schedules; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
114
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wago over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2012
13 years ago
Most Recent CVE
Dec 10, 2025
226 days ago

Products(347 total)

Top CVEs

Signals from CVEs in this vendor scope (114 CVEs).

114 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1698CRITICAL
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behav
May 15, 20239.883NOYES
CVE-2018-12980HIGH
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to
Jul 12, 20188.853NOYES
CVE-2020-8597CRITICAL
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
Feb 3, 20209.841NONO
CVE-2018-12979MEDIUM
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by
Jul 12, 20186.534NOYES
CVE-2019-12549CRITICAL
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the cor
Jun 17, 20199.833NONO
CVE-2021-30188CRITICAL
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
May 25, 20219.832NONO
CVE-2019-12550CRITICAL
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
Jun 17, 20199.832NONO
CVE-2025-41732CRITICAL
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device
Dec 10, 20259.831NONO
CVE-2025-41730CRITICAL
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full devic
Dec 10, 20259.831NONO
CVE-2021-34569CRITICAL
In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.
Nov 9, 20229.831NONO
View all 114 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products114 CVEs
21%
45%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local27 (23.7%)
Network85 (74.6%)
Unknown2 (1.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low108 (94.7%)
High4 (3.5%)
Unknown2 (1.8%)
User Interaction
None104 (91.2%)
Unknown2 (1.8%)
Required8 (7.0%)
Privileges Required
Low31 (27.2%)
High9 (7.9%)
None72 (63.2%)
Unknown2 (1.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (114 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.9% of CVEs· 95th percentile
ExploitDB
3 CVEs
2.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wago.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wago — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wago's Products

View all 4 CNAs →

Top CWEs