Description
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.
Published: 2026-07-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A diagnostic interface is inadvertently enabled on WAGO Field I/O Profinet devices during the earlyuthenticated attacker direct contact with internal system processes. Once accessed, the attacker can execute arbitrary commands and achieve full system compromise. The weakness is a form of improper restriction of capabilities (CWE‑912), allowing privileged operations without credential enforcement.

Affected Systems

Devices in the WAGO System I/O Field Profinet series, including the models 0765‑110x, 0765‑120x, 0765‑150x, 0765‑2101, 0765‑2102, 0765‑410x, 0765‑420x, and 0765‑450x, are affected. Firmware version 1.2.1.0 is vulnerable, and the vulnerability may persist in versions that have not been patched by WAGO.

Risk and Exploitability

The CVSS score of 9.3 classifies the vulnerability as critical. The EPSS score of less than 1% indicates a very low probability of exploitation. There is no KEV listing, which does not reduce the risk, because the attack surface remains open during boot and no authentication is required. The likely attack vector is an unauthenticated remote attacker connecting to the device during the brief boot window; the impact is full system compromise, making the risk high with moderate to high exploitability for systems lacking network segmentation or timely firmware updates.

Generated by OpenCVE AI on August 1, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest firmware from WAGO that removes or disables the undocumented diagnostic interface.
  • During the boot period, restrict network access to the device by blocking traffic to its diagnostic ports or IP address with firewall rules or network segmentation.
  • Enable logging of boot‑time activity and monitor logs for any unexpected use of the diagnostic interface, and investigate such events promptly.

Generated by OpenCVE AI on August 1, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Wago 0765-110x/0100-0000
Wago 0765-120x/0100-0000
Wago 0765-150x/0100-0000
Wago 0765-2101/0100-0000
Wago 0765-2102/0100-0000
Wago 0765-410x/0100-0000
Wago 0765-420x/0100-0000
Wago 0765-450x/0100-0000
Vendors & Products Wago 0765-110x/0100-0000
Wago 0765-120x/0100-0000
Wago 0765-150x/0100-0000
Wago 0765-2101/0100-0000
Wago 0765-2102/0100-0000
Wago 0765-410x/0100-0000
Wago 0765-420x/0100-0000
Wago 0765-450x/0100-0000

Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.
Title Unauthenticated Access to Internal Diagnostic Interface
First Time appeared Wago
Wago field Profinet
Weaknesses CWE-912
CPEs cpe:2.3:o:wago:field_profinet:*:*:*:*:*:*:*:*
cpe:2.3:o:wago:field_profinet:1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Wago
Wago field Profinet
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Wago 0765-110x/0100-0000 0765-120x/0100-0000 0765-150x/0100-0000 0765-2101/0100-0000 0765-2102/0100-0000 0765-410x/0100-0000 0765-420x/0100-0000 0765-450x/0100-0000 Field Profinet
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-07-13T14:44:48.962Z

Reserved: 2026-03-24T13:19:36.714Z

Link: CVE-2026-4769

cve-icon Vulnrichment

Updated: 2026-07-13T14:44:44.417Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses