Impact
A diagnostic interface is inadvertently enabled on WAGO Field I/O Profinet devices during the earlyuthenticated attacker direct contact with internal system processes. Once accessed, the attacker can execute arbitrary commands and achieve full system compromise. The weakness is a form of improper restriction of capabilities (CWE‑912), allowing privileged operations without credential enforcement.
Affected Systems
Devices in the WAGO System I/O Field Profinet series, including the models 0765‑110x, 0765‑120x, 0765‑150x, 0765‑2101, 0765‑2102, 0765‑410x, 0765‑420x, and 0765‑450x, are affected. Firmware version 1.2.1.0 is vulnerable, and the vulnerability may persist in versions that have not been patched by WAGO.
Risk and Exploitability
The CVSS score of 9.3 classifies the vulnerability as critical. The EPSS score of less than 1% indicates a very low probability of exploitation. There is no KEV listing, which does not reduce the risk, because the attack surface remains open during boot and no authentication is required. The likely attack vector is an unauthenticated remote attacker connecting to the device during the brief boot window; the impact is full system compromise, making the risk high with moderate to high exploitability for systems lacking network segmentation or timely firmware updates.
OpenCVE Enrichment