Description
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
Published: 2026-10-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution via path traversal
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a path traversal flaw in the handling of BACnet File Objects. An attacker can craft a file object name that is interpreted as a file path, and because the system does not validate or constrain the path, they can reference files outside the intended directory. By sending such a request to the device, the attacker can read any file accessible to the device or overwrite a file, allowing full system compromise if critical configuration or binary files are affected.

Affected Systems

The affected equipment is manufactured by WAGO and includes the 0750 series (models 811x and 821x), the 0751‑9x01 model, the 0752‑8303‑8000‑0002 model, and a variety of 0762 series models (340x, 420x‑8000‑000x, 430x‑8000‑000x, 520x‑8000‑000x, 530x‑8000‑000x, 620x‑8000‑000x, 630x‑8000‑000x). These devices are deployed in industrial control systems, building automation, and factory automation environments where BACnet is used to exchange data.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity level. Although there is no publicly available EPSS score, the vulnerability is unauthenticated and reachable via the BACnet protocol, making it highly exploitable. It is not listed in the CISA KEV catalog, suggesting no confirmed wild exploitation yet, but an attacker could use any network‑connected host to send a crafted request, read or write arbitrary files, and potentially compromise the entire device.

Generated by OpenCVE AI on October 1, 2026 at 07:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied security patch that adds proper validation for file object names.
  • If BACnet File Object creation is not required for your deployment, disable this feature or configure it to accept requests only from trusted control‑system hosts.
  • Implement network access controls (ACLs or firewalls) to restrict BACnet traffic to authorized hosts and isolate the device from unmanaged networks.

Generated by OpenCVE AI on October 1, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
Title Path traversal in dynamically created BACnet File Objects
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-10-01T06:42:00.734Z

Reserved: 2025-04-16T11:18:45.759Z

Link: CVE-2025-41753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T07:16:32.473

Modified: 2026-10-01T07:16:32.473

Link: CVE-2025-41753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')