Summary
Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).
Impact
Exploitation of these vulnerabilities can cause denial‑of‑service conditions on affected WAGO PLCs and communication components, disrupting industrial control operations. Additionally, opening manipulated CODESYS project files may trigger arbitrary code execution in the user context, compromising system integrity, confidentiality, and availability.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| 0750-811?-????-???? | 0750-811x-xxxx-xxxx | wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70) |
| 0751-9?01 | 0751-9x01 | wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70) |
| 0752-8303/8000-0002 | 0752-8303/8000-0002 | wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70) |
| 0762-340? | 0762-340x | custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32) |
| 0762-420?/8000-000? | 0762-420x/8000-000x | custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32) |
| 0762-430?/8000-000? | 0762-430x/8000-000x | custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32) |
| 0762-520?/8000-000? | 0762-520x/8000-000x | wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70) |
| 0762-530?/8000-000? | 0762-530x/8000-000x | wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70) |
| 0762-620?/8000-000? | 0762-620x/8000-000x | custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32) |
| 0762-630?/8000-000? | 0762-630x/8000-000x | custom wago_os_linux <4.10.0 (70), wago_os_linux <4.10.0 (FW32) |
| 750-821?-????-???? | 750-821x-xxx-xxx | wago_os_linux <4.10.0 (FW32), custom wago_os_linux <4.10.0 (70) |
Vulnerabilities
Expand / Collapse allAn unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
Remediation
Update to Firmware version 4.10.0 (FW32) or higher. For the latest Custom Firmware please contact the WAGO support.
Acknowledgments
WAGO GmbH & Co. KG thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 10/01/2026 12:00 | Release version. |