← back
CVE-2020-12506criticalCWE-306

WAGO: Authentication Bypass Vulnerability in WAGO 750-36X and WAGO 750-8XX Versions <= FW03

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 1.5%
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
In short

WAGO industrial controllers with firmware version 3 or earlier allow attackers to modify device settings without needing a password or login credentials. This is critical because these devices control industrial equipment, and unauthorized changes could disrupt operations or cause safety hazards.

Technical detail

Improper authentication implementation in WAGO 750-series PLCs (versions ≤FW03) enables unauthenticated modification of device configuration via crafted requests. The vulnerability requires network access to the affected device but no credentials, allowing an attacker to alter critical operational settings with direct impact on industrial control system integrity and availability.

Summary generated and translated by AI from the official description.
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H