Zurück zur Übersicht

WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE

VDE-2025-081
Last update
01.10.2026 12:00
Published at
01.10.2026 12:00
Vendor(s)
WAGO GmbH & Co. KG
External ID
VDE-2025-081
CSAF Document

Summary

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

Impact

Exploitation of these vulnerabilities can cause denial‑of‑service conditions on affected WAGO PLCs and communication components, disrupting industrial control operations. Additionally, opening manipulated CODESYS project files may trigger arbitrary code execution in the user context, compromising system integrity, confidentiality, and availability.

Affected Product(s)

Model no. Product name Affected versions
0750-811?-????-???? 0750-811x-xxxx-xxxx wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70)
0751-9?01 0751-9x01 wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70)
0752-8303/8000-0002 0752-8303/8000-0002 wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70)
0762-340? 0762-340x custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32)
0762-420?/8000-000? 0762-420x/8000-000x custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32)
0762-430?/8000-000? 0762-430x/8000-000x custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32)
0762-520?/8000-000? 0762-520x/8000-000x wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70)
0762-530?/8000-000? 0762-530x/8000-000x wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70)
0762-620?/8000-000? 0762-620x/8000-000x custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32)
0762-630?/8000-000? 0762-630x/8000-000x custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32)
750-821?-????-???? 750-821x-xxx-xxx wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70)

Vulnerabilities

Expand / Collapse all

Published
01.10.2026 08:42
Weakness
Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
Summary

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

References

Published
01.10.2026 08:42
Weakness
Out-of-bounds Read (CWE-125)
Summary

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.

References

Published
01.10.2026 08:42
Weakness
Deserialization of Untrusted Data (CWE-502)
Summary

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

References

Remediation

Update to Firmware version 4.10.0 (FW32) or higher. For the latest Custom Firmware please contact the WAGO support.

Acknowledgments

WAGO GmbH & Co. KG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 01.10.2026 12:00 Release version.