CVE-2025-25264
Overly Permissive CORS Policy in WAGO Device Manager
An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Productos afectados
WAGO · CC100 0751-9x01WAGO · Edge Controller 0752-8303/8000-0002WAGO · PFC100 G1 0750-810x/xxxx-xxxxWAGO · PFC100 G2 0750-811x-xxxx-xxxxWAGO · PFC200 G1 750-820x-xxx-xxxWAGO · PFC200 G2 750-821x-xxx-xxxWAGO · TP600 0762-420x/8000-000xWAGO · TP600 0762-430x/8000-000xWAGO · TP600 0762-520x/8000-000xWAGO · TP600 0762-530x/8000-000xWAGO · TP600 0762-620x/8000-000xWAGO · TP600 0762-630x/8000-000x¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →