Impact
This vulnerability is a path traversal flaw in the handling of BACnet File Objects. An attacker can craft a file object name that is interpreted as a file path, and because the system does not validate or constrain the path, they can reference files outside the intended directory. By sending such a request to the device, the attacker can read any file accessible to the device or overwrite a file, allowing full system compromise if critical configuration or binary files are affected.
Affected Systems
The affected equipment is manufactured by WAGO and includes the 0750 series (models 811x and 821x), the 0751‑9x01 model, the 0752‑8303‑8000‑0002 model, and a variety of 0762 series models (340x, 420x‑8000‑000x, 430x‑8000‑000x, 520x‑8000‑000x, 530x‑8000‑000x, 620x‑8000‑000x, 630x‑8000‑000x). These devices are deployed in industrial control systems, building automation, and factory automation environments where BACnet is used to exchange data.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity level. Although there is no publicly available EPSS score, the vulnerability is unauthenticated and reachable via the BACnet protocol, making it highly exploitable. It is not listed in the CISA KEV catalog, suggesting no confirmed wild exploitation yet, but an attacker could use any network‑connected host to send a crafted request, read or write arbitrary files, and potentially compromise the entire device.
OpenCVE Enrichment